Skip to content

fix(webview): route webview:changed only to its owner in multi-user mode - #501

Merged
Ark0N merged 1 commit into
Ark0N:masterfrom
aakhter:pr/webview-sse-owner
Sep 28, 2026
Merged

Ark0N merged 1 commit into
Ark0N:masterfrom
aakhter:pr/webview-sse-owner

Conversation

@aakhter

@aakhter aakhter commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

What

In multi-user mode, every connected SSE client received webview:changed, so any user saw the ids of other users' web-tab creates, edits and deletes. webview-routes.ts broadcast { action, id } with no owner, and the server's SSE routing hint has branches for tab:, the session prefixes, remote: and clipboard: but none for webview:, so the hint came back undefined and the event went to everyone.

How

  • The three webview:changed broadcasts now carry owner: ownerLayoutKey(<record>.owner). The owner comes from the stored web-tab record, not from whoever made the request, so when an admin edits or deletes a user's tab, that user is notified.
  • New src/web/webview-sse.ts (deriveWebviewSseHint, 6 lines) returns { username: owner, sessionScoped: true }, and server.ts routes webview: events through it, next to the existing tab: branch.
  • Result: the owner plus admins receive the event; other users don't. A missing owner reaches admins only.
  • Single-user delivery is unchanged. The payload gains owner: '@single', an optional field (non-breaking per docs/versioning-policy.md). webview-tabs.js only reads action and id before re-fetching, so it ignores it. The sse-events.ts doc comment lists the new field.

Testing

  • test/webview-sse.test.ts (7) runs the real server hint function and the routes end to end. The multi-user isolation tests failed before the fix (bob received alice's create, update and delete). Removing the new webview: branch makes 4 of them fail; the 3 single-user tests pass either way, as they should.
  • Existing suites pass unchanged, including webview-routes (27), tab-layout-sse (8) and sse-registry-parity (4).
  • typecheck, lint, format:check and build are clean.

webview:changed carried only {action, id} and the SSE routing hint had no
webview: branch, so every connected client received it: in multi-user mode
any user saw the ids of other users' web-tab creates, edits and deletes.
The event now carries the web tab's owner (from the stored record) and is
routed to that owner plus admins. Single-user delivery is unchanged.
@Ark0N
Ark0N merged commit 614c7e6 into Ark0N:master Sep 28, 2026
2 checks passed
@Ark0N

Ark0N commented Sep 28, 2026

Copy link
Copy Markdown
Owner

Merged, and it ships in 1.33.2. Thanks @aakhter.

This was a real leak in multi-user mode and the fix is exactly the right size: the owner comes from the stored web-tab record rather than from whoever made the request, so an admin editing someone's tab still notifies that person, and the new webview: branch mirrors the existing tab: routing instead of inventing a new pattern. The isolation tests going through the real server hint are what made this an easy merge. Merged as it was, no changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants