fix(web): make Add Section work on insecure (plain-HTTP) origins
Both add-section paths on Settings > Home Screen called crypto.randomUUID() unguarded. Browsers only expose randomUUID in secure contexts, so on self-hosted servers accessed over plain HTTP the click handler threw synchronously and the Add section button appeared dead while Cancel still worked. api/client.ts and plexAuth.ts already carried ad-hoc fallbacks for the same problem; extract a shared lib/uuid helper (UUIDv4 via crypto.getRandomValues, available in insecure contexts) and use it at all four call sites. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
5d7eec7a62
commit
82379fa3e2
+4
-18
@@ -1,5 +1,6 @@
|
||||
import type { ApiError, RefreshResponse } from "./types";
|
||||
import { storage } from "../utils/storage";
|
||||
import { randomUUID } from "../lib/uuid";
|
||||
|
||||
type ProfileUnverifiedListener = () => void;
|
||||
let profileUnverifiedListener: ProfileUnverifiedListener | null = null;
|
||||
@@ -82,25 +83,14 @@ export function getProfileToken(): string | null {
|
||||
return profileToken;
|
||||
}
|
||||
|
||||
function getOrCreateDeviceId(): string | null {
|
||||
function getOrCreateDeviceId(): string {
|
||||
const existing = storage.get(storage.KEYS.DEVICE_ID);
|
||||
if (existing) {
|
||||
return existing;
|
||||
}
|
||||
|
||||
let nextId: string | null = null;
|
||||
try {
|
||||
nextId =
|
||||
typeof crypto !== "undefined" && typeof crypto.randomUUID === "function"
|
||||
? crypto.randomUUID()
|
||||
: `web-${Date.now().toString(36)}-${Math.random().toString(36).slice(2, 10)}`;
|
||||
} catch {
|
||||
nextId = `web-${Date.now().toString(36)}-${Math.random().toString(36).slice(2, 10)}`;
|
||||
}
|
||||
|
||||
if (nextId) {
|
||||
storage.set(storage.KEYS.DEVICE_ID, nextId);
|
||||
}
|
||||
const nextId = randomUUID();
|
||||
storage.set(storage.KEYS.DEVICE_ID, nextId);
|
||||
return nextId;
|
||||
}
|
||||
|
||||
@@ -137,10 +127,6 @@ function detectDeviceName(): string {
|
||||
|
||||
function getDeviceHeaders(): Record<string, string> {
|
||||
const deviceId = getOrCreateDeviceId();
|
||||
if (!deviceId) {
|
||||
return {};
|
||||
}
|
||||
|
||||
return {
|
||||
"X-Silo-Device-Id": deviceId,
|
||||
"X-Silo-Device-Name": detectDeviceName(),
|
||||
|
||||
Reference in New Issue
Block a user