Cache the page-owned app response before starting the worker

This commit is contained in:
Jonathan Sykes
2026-10-08 09:04:20 +08:00
parent e7a7cdc6b9
commit a86fa1cebe
16 changed files with 186 additions and 17 deletions

View File

@@ -88,3 +88,15 @@ test('index embeds build-local group hashes without recursively embedding index/
const legacy=JSON.parse(off.index.match(/id="ytp-assets">([^<]+)<\/script>/)[1]);
expect(legacy.files['/app.js'].h).toBe(off.manifest.buildTag);
}));
test('app bootstrap CSP hash follows exact app bytes and rollback keeps external execution',()=>fixture(dir=>{
writeFileSync(join(dir,'index.html'),'<meta http-equiv="Content-Security-Policy" content="script-src \'self\' \'sha256-__APP_SCRIPT_HASH__\'"><script type="application/json" id="ytp-assets">{}</script>');
const result=createAssetManifest(dir),digest=createHash('sha256').update('window.app=1').digest('base64');
expect(result.index).toContain("'sha256-"+digest+"'");
expect(JSON.parse(result.index.match(/id="ytp-assets">([^<]+)</)[1]).appCache).toBe(true);
expect(JSON.parse(createAssetManifest(dir,{assetSync:false}).index.match(/id="ytp-assets">([^<]+)</)[1]).appCache).toBe(false);
expect(JSON.parse(createAssetManifest(dir,{hashing:false}).index.match(/id="ytp-assets">([^<]+)</)[1]).appCache).toBe(false);
writeFileSync(join(dir,'app.js'),'window.app=2');
expect(createAssetManifest(dir).index).not.toContain(digest);
}));