Preserve verified N-1 app boot after a cache entry is lost

This commit is contained in:
Jonathan Sykes
2026-10-08 09:10:28 +08:00
parent 639f0a2257
commit 3505dc3c0e
2 changed files with 49 additions and 18 deletions

View File

@@ -12,26 +12,46 @@
// consumption can finish after that event; boot exactly once in that case.
if(domReady)root.boot();
}
async function external(url) {
await new Promise((resolve,reject)=>{
const node=doc.createElement('script');node.src=url;
node.onload=()=>{if(domReady&&!appSawDom)root.boot();resolve();};node.onerror=()=>reject(Error('Unable to load player'));
doc.head.append(node);
});
}
async function verified(response, expected) {
const bytes=await response.clone().arrayBuffer();
const digest=new Uint8Array(await root.crypto.subtle.digest('SHA-256',bytes));
const hex=Array.from(digest,b=>b.toString(16).padStart(2,'0')).join('');
if(hex.slice(0,10)!==expected)throw Error('Player body hash mismatch');
return {bytes,digest};
}
async function start() {
if(!manifest.appCache || !root.crypto?.subtle) {
await new Promise((resolve,reject)=>{
const node=doc.createElement('script');node.src=key;
node.onload=()=>{if(domReady&&!appSawDom)root.boot();resolve();};node.onerror=()=>reject(Error('Unable to load player'));
doc.head.append(node);
});
return;
}
if(!manifest.appCache || !root.crypto?.subtle)return external(key);
const expected=manifest.files['/app.js'].h;
let cache;
try { cache=await root.caches?.open('ytplayer-assets'); } catch {}
let response=await cache?.match(key);
if(!response || response.headers.get('X-Asset-Hash')!==expected)response=await (root.Lazy.appResponse || root.fetch(key,{credentials:'same-origin'}));
if(!response.ok || response.headers.get('X-Asset-Hash')!==expected)throw Error('Player asset hash mismatch');
const bytes=await response.clone().arrayBuffer();
const digest=new Uint8Array(await root.crypto.subtle.digest('SHA-256',bytes));
const hex=Array.from(digest,b=>b.toString(16).padStart(2,'0')).join('');
if(!response || response.headers.get('X-Asset-Hash')!==expected) {
try { response=await (root.Lazy.appResponse || root.fetch(key,{credentials:'same-origin'})); } catch {}
}
if(!response?.ok || response.headers.get('X-Asset-Hash')!==expected) {
// Preserve staged N-1 boot after an individual cache eviction. Only the
// controller can serve this old URL safely; never fetch stale URLs bare.
const state=cache && await root.AssetSyncCore.state(cache);
const previousKey=state && root.AssetSyncCore.fallback(manifest,state.previous,'/app.js');
const previous=previousKey && await cache.match(previousKey);
const previousHash=state?.previous?.files['/app.js']?.h;
if(root.navigator?.serviceWorker?.controller && previous?.ok && previous.headers.get('X-Asset-Hash')===previousHash) {
await verified(previous,previousHash);
delete root.Lazy.appResponse;
return external(previousKey);
}
throw Error('Player asset hash mismatch');
}
const {bytes,digest}=await verified(response,expected);
const permission="'sha256-"+root.btoa(String.fromCharCode(...digest))+"'";
if(hex.slice(0,10)!==expected || !doc.querySelector('meta[http-equiv="Content-Security-Policy"]').content.includes(permission))throw Error('Player body hash mismatch');
if(!doc.querySelector('meta[http-equiv="Content-Security-Policy"]').content.includes(permission))throw Error('Player body hash mismatch');
// CacheStorage may share a full quota with saved music. Never remove data
// to make room; boot from these verified bytes even if caching is refused.
try { await cache?.put(key,response); } catch(error) { root.console.warn('[app-cache]',error.message); }