fix: make Service Worker cache and removal outcomes truthful
SW-URL-01: canonicalize each generated root-relative manifest URL against the registration scope once, re-check same-origin, and share that absolute identity across install cache keys, fetch classification and cache lookup or delete. Previously every verified asset fell through to the network. SW-01: serve verified static requests only from the current release cache. A CacheStorage-wide match could return a previous release's response for the same URL while the delete targeted a cache that was never read. The worker scope facade no longer exposes a wide match at all. SW-02: cache reset deletes only names that parse as owned, so a foreign cache sharing the ca-static-v1- prefix survives. SW-03: unregister() resolving to false is a FAILED unregister, not UNREGISTERED. SW-04: staged removal reports what happened - ABSENT, UNREGISTERED and PURGED map to DISABLED, OWNERSHIP_MISMATCH to INCOMPATIBLE and FAILED to FAILED - so a later release cannot delete the worker while a registration or owned cache is still present. SW-05: add the runtime-neutral service-worker-static-manifest codec that owns exact row keys, the extension and content-type allowlist, the root-relative URL rule and the length-prefixed canonical bytes. The generator and the build gate hash those same bytes, and the build gate now decodes and recomputes the set digest instead of type-casting the manifest. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
cc4e875c2d
commit
58efe6ddbd
@@ -1,9 +1,31 @@
|
||||
import { createHash } from "node:crypto";
|
||||
|
||||
import { describe, expect, it } from "vitest";
|
||||
|
||||
import { resolveServiceWorkerBuildInput } from "../../scripts/lib/service-worker-build-input.ts";
|
||||
import {
|
||||
canonicalStaticManifestBytes,
|
||||
type StaticAssetRow,
|
||||
} from "../../src/contracts/service-worker-static-manifest.ts";
|
||||
|
||||
const digest = (character: string) => `sha256:${character.repeat(64)}`;
|
||||
|
||||
/** SW-05. The gate recomputes this from the shared canonical bytes. */
|
||||
function setDigestFor(rows: readonly StaticAssetRow[]): string {
|
||||
return `sha256:${createHash("sha256")
|
||||
.update(canonicalStaticManifestBytes(rows))
|
||||
.digest("hex")}`;
|
||||
}
|
||||
|
||||
const ASSET_ROWS: readonly StaticAssetRow[] = Object.freeze([
|
||||
Object.freeze({
|
||||
url: "/assets/app.0123456789abcdef.js",
|
||||
sha256: digest("c"),
|
||||
bytes: 128,
|
||||
contentType: "text/javascript",
|
||||
}),
|
||||
]);
|
||||
|
||||
describe("service worker build input", () => {
|
||||
const selection = {
|
||||
mode: "ACTIVE" as const,
|
||||
@@ -14,8 +36,8 @@ describe("service worker build input", () => {
|
||||
schemaVersion: 1 as const,
|
||||
buildId: "build-1",
|
||||
releaseId: "release-1",
|
||||
setDigest: digest("a"),
|
||||
assets: [],
|
||||
setDigest: setDigestFor(ASSET_ROWS),
|
||||
assets: [...ASSET_ROWS],
|
||||
};
|
||||
|
||||
it("rejects a direct worker build when ACTIVE selection or generated inputs are absent", () => {
|
||||
@@ -84,4 +106,90 @@ describe("service worker build input", () => {
|
||||
releaseManifestUrl: "/release-manifest.json",
|
||||
});
|
||||
});
|
||||
|
||||
it("rejects asset row or canonical set-digest tampering at build input", () => {
|
||||
const base = {
|
||||
selection,
|
||||
contractSet: { setDigest: digest("b") },
|
||||
runtimeConfig: { RELEASE_MANIFEST_URL: "/release-manifest.json" },
|
||||
buildId: "build-1",
|
||||
releaseId: "release-1",
|
||||
};
|
||||
const tampered: readonly Readonly<{
|
||||
label: string;
|
||||
assets: unknown;
|
||||
}>[] = [
|
||||
{
|
||||
label: "stale set digest",
|
||||
assets: { ...assets, setDigest: digest("a") },
|
||||
},
|
||||
{
|
||||
label: "tampered byte length",
|
||||
assets: {
|
||||
...assets,
|
||||
assets: [{ ...ASSET_ROWS[0]!, bytes: 129 }],
|
||||
},
|
||||
},
|
||||
{
|
||||
label: "cross-origin url",
|
||||
assets: {
|
||||
...assets,
|
||||
assets: [
|
||||
{ ...ASSET_ROWS[0]!, url: "https://evil.example/a.js" },
|
||||
],
|
||||
},
|
||||
},
|
||||
{
|
||||
label: "dot segment",
|
||||
assets: {
|
||||
...assets,
|
||||
assets: [{ ...ASSET_ROWS[0]!, url: "/assets/../a.js" }],
|
||||
},
|
||||
},
|
||||
{
|
||||
label: "extension and content type mismatch",
|
||||
assets: {
|
||||
...assets,
|
||||
assets: [{ ...ASSET_ROWS[0]!, contentType: "text/css" }],
|
||||
},
|
||||
},
|
||||
{
|
||||
label: "unknown row field",
|
||||
assets: {
|
||||
...assets,
|
||||
assets: [{ ...ASSET_ROWS[0]!, extra: "smuggled" }],
|
||||
},
|
||||
},
|
||||
{
|
||||
label: "duplicate url",
|
||||
assets: {
|
||||
...assets,
|
||||
assets: [ASSET_ROWS[0]!, ASSET_ROWS[0]!],
|
||||
},
|
||||
},
|
||||
];
|
||||
for (const entry of tampered) {
|
||||
expect(
|
||||
() =>
|
||||
resolveServiceWorkerBuildInput({
|
||||
...base,
|
||||
assets: entry.assets as never,
|
||||
}),
|
||||
entry.label,
|
||||
).toThrow(TypeError);
|
||||
}
|
||||
});
|
||||
|
||||
it("accepts generator-shaped output unchanged", () => {
|
||||
expect(() =>
|
||||
resolveServiceWorkerBuildInput({
|
||||
selection,
|
||||
assets,
|
||||
contractSet: { setDigest: digest("b") },
|
||||
runtimeConfig: { RELEASE_MANIFEST_URL: "/release-manifest.json" },
|
||||
buildId: "build-1",
|
||||
releaseId: "release-1",
|
||||
}),
|
||||
).not.toThrow();
|
||||
});
|
||||
});
|
||||
|
||||
@@ -118,6 +118,253 @@ function workerScope() {
|
||||
return { scope, clients, deleted };
|
||||
}
|
||||
|
||||
describe("service worker static cache authority", () => {
|
||||
const setDigest = `sha256:${"c".repeat(64)}` as const;
|
||||
const currentCacheName = `${STATIC_CACHE_PREFIX}${setDigest.slice(
|
||||
"sha256:".length,
|
||||
"sha256:".length + 16,
|
||||
)}`;
|
||||
|
||||
function staticRuntime(
|
||||
caches: Readonly<{
|
||||
open: (name: string) => Promise<unknown>;
|
||||
keys: () => Promise<readonly string[]>;
|
||||
delete: (name: string) => Promise<boolean>;
|
||||
}>,
|
||||
) {
|
||||
return createServiceWorkerRuntime(
|
||||
{
|
||||
caches,
|
||||
clients: { matchAll: vi.fn(async () => []) },
|
||||
registrationScope: `${ORIGIN}/app/`,
|
||||
skipWaiting: vi.fn(async () => {}),
|
||||
fetcher: vi.fn(),
|
||||
digest: vi.fn(),
|
||||
} as never,
|
||||
{
|
||||
identity: { ...identity, staticAssetSetDigest: setDigest },
|
||||
handlers: ["PWA_STATIC_ASSETS"],
|
||||
manifest: {
|
||||
schemaVersion: 1,
|
||||
buildId: identity.buildId,
|
||||
releaseId: identity.releaseId,
|
||||
setDigest,
|
||||
// SW-URL-01. Generator output is root-relative.
|
||||
assets: [
|
||||
{
|
||||
url: "/assets/app.0123456789abcdef.js",
|
||||
sha256: `sha256:${"d".repeat(64)}`,
|
||||
bytes: 10,
|
||||
contentType: "text/javascript",
|
||||
},
|
||||
],
|
||||
},
|
||||
runtimeConfigUrl: "/runtime-config.json",
|
||||
releaseManifestUrl: "/release-manifest.json",
|
||||
},
|
||||
);
|
||||
}
|
||||
|
||||
it("classifies a generated root-relative asset against an absolute Request URL", async () => {
|
||||
const currentResponse = new Response("current", { status: 200 });
|
||||
const opened: string[] = [];
|
||||
const runtime = staticRuntime({
|
||||
open: vi.fn(async (name: string) => {
|
||||
opened.push(name);
|
||||
return {
|
||||
match: async () => currentResponse.clone(),
|
||||
delete: async () => true,
|
||||
};
|
||||
}),
|
||||
keys: vi.fn(async () => [currentCacheName]),
|
||||
delete: vi.fn(async () => true),
|
||||
});
|
||||
|
||||
const served = await runtime.onFetch({
|
||||
method: "GET",
|
||||
url: `${ORIGIN}/assets/app.0123456789abcdef.js`,
|
||||
});
|
||||
expect(served).not.toBeNull();
|
||||
expect(opened).toEqual([currentCacheName]);
|
||||
});
|
||||
|
||||
it("matches static responses only in the current release cache", async () => {
|
||||
const previousCacheName = `${STATIC_CACHE_PREFIX}${"e".repeat(16)}`;
|
||||
const previousMatch = vi.fn(
|
||||
async () => new Response("previous", { status: 200 }),
|
||||
);
|
||||
const runtime = staticRuntime({
|
||||
open: vi.fn(
|
||||
async (
|
||||
name: string,
|
||||
): Promise<Readonly<{ match: unknown; delete: unknown }>> =>
|
||||
name === previousCacheName
|
||||
? {
|
||||
match: previousMatch,
|
||||
delete: async (): Promise<boolean> => true,
|
||||
}
|
||||
: {
|
||||
match: async (): Promise<Response | undefined> => undefined,
|
||||
delete: async (): Promise<boolean> => true,
|
||||
},
|
||||
),
|
||||
keys: vi.fn(async () => [currentCacheName, previousCacheName]),
|
||||
delete: vi.fn(async () => true),
|
||||
});
|
||||
|
||||
// Only the previous cache holds the entry, so the request falls through to
|
||||
// the network rather than serving a stale release.
|
||||
await expect(
|
||||
runtime.onFetch({
|
||||
method: "GET",
|
||||
url: `${ORIGIN}/assets/app.0123456789abcdef.js`,
|
||||
}),
|
||||
).resolves.toBeNull();
|
||||
expect(previousMatch).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it("deletes an invalid hit only from the current release cache", async () => {
|
||||
const deletes: string[] = [];
|
||||
const runtime = staticRuntime({
|
||||
open: vi.fn(async (name: string) => ({
|
||||
match: async () => new Response("bad", { status: 500 }),
|
||||
delete: async (url: string): Promise<boolean> => {
|
||||
deletes.push(`${name}:${url}`);
|
||||
return true;
|
||||
},
|
||||
})),
|
||||
keys: vi.fn(async () => [currentCacheName]),
|
||||
delete: vi.fn(async () => true),
|
||||
});
|
||||
|
||||
await expect(
|
||||
runtime.onFetch({
|
||||
method: "GET",
|
||||
url: `${ORIGIN}/assets/app.0123456789abcdef.js`,
|
||||
}),
|
||||
).resolves.toBeNull();
|
||||
expect(deletes).toEqual([
|
||||
`${currentCacheName}:${ORIGIN}/assets/app.0123456789abcdef.js`,
|
||||
]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("service worker exact ownership and truthful removal", () => {
|
||||
it("deletes only exact owned static cache names", async () => {
|
||||
const fixture = workerScope();
|
||||
fixture.scope.caches.keys = vi.fn(async () => [
|
||||
`${STATIC_CACHE_PREFIX}${"a".repeat(16)}`,
|
||||
`${STATIC_CACHE_PREFIX}${"b".repeat(16)}`,
|
||||
// SW-02. Same prefix, not owned.
|
||||
`${STATIC_CACHE_PREFIX}not-owned`,
|
||||
`${STATIC_CACHE_PREFIX}${"c".repeat(17)}`,
|
||||
`${STATIC_CACHE_PREFIX}${"A".repeat(16)}`,
|
||||
"foreign-cache",
|
||||
]);
|
||||
const runtime = createServiceWorkerRuntime(fixture.scope as never, {
|
||||
identity,
|
||||
handlers: [],
|
||||
manifest: null,
|
||||
runtimeConfigUrl: "/runtime-config.json",
|
||||
releaseManifestUrl: "/release-manifest.json",
|
||||
});
|
||||
const request = createServiceWorkerMessage({
|
||||
kind: "CACHE_RESET_REQUEST",
|
||||
sourceBuildId: "page-build",
|
||||
targetBuildId: identity.buildId,
|
||||
nonce: "nonce-reset-0001",
|
||||
});
|
||||
await runtime.onCacheResetRequest(request, fixture.clients[0] as never);
|
||||
|
||||
expect(fixture.deleted).toEqual([
|
||||
`${STATIC_CACHE_PREFIX}${"a".repeat(16)}`,
|
||||
`${STATIC_CACHE_PREFIX}${"b".repeat(16)}`,
|
||||
]);
|
||||
});
|
||||
it.each([
|
||||
{
|
||||
label: "unregister false",
|
||||
unregister: async () => false,
|
||||
expected: { kind: "FAILED" },
|
||||
},
|
||||
{
|
||||
label: "unregister rejects",
|
||||
unregister: async () => {
|
||||
throw new TypeError("unregister exploded");
|
||||
},
|
||||
expected: { kind: "FAILED" },
|
||||
},
|
||||
{
|
||||
label: "unregister true",
|
||||
unregister: async () => true,
|
||||
expected: { kind: "DISABLED" },
|
||||
},
|
||||
])(
|
||||
"does not hide $label behind DISABLED",
|
||||
async ({ unregister, expected }) => {
|
||||
const registration = {
|
||||
scope: `${ORIGIN}/`,
|
||||
installing: null,
|
||||
waiting: null,
|
||||
active: { scriptURL: SCRIPT_URL },
|
||||
unregister: vi.fn(unregister),
|
||||
update: vi.fn(async () => {}),
|
||||
} as unknown as ServiceWorkerRegistration;
|
||||
const controller = createServiceWorkerPageController({
|
||||
container: {
|
||||
controller: null,
|
||||
register: vi.fn(),
|
||||
getRegistration: vi.fn(async () => registration),
|
||||
addEventListener: vi.fn(),
|
||||
removeEventListener: vi.fn(),
|
||||
} as never,
|
||||
routerBasePath: "/",
|
||||
origin: ORIGIN,
|
||||
selection: {
|
||||
mode: "REMOVE_REGISTRATION",
|
||||
scriptPath: "service-worker.js",
|
||||
handlers: [],
|
||||
},
|
||||
} as never);
|
||||
|
||||
await expect(controller.start()).resolves.toMatchObject(expected);
|
||||
},
|
||||
);
|
||||
|
||||
it("reports an ownership mismatch as INCOMPATIBLE rather than DISABLED", async () => {
|
||||
const foreign = {
|
||||
scope: `${ORIGIN}/`,
|
||||
installing: null,
|
||||
waiting: null,
|
||||
active: { scriptURL: `${ORIGIN}/someone-else.js` },
|
||||
unregister: vi.fn(async () => true),
|
||||
update: vi.fn(async () => {}),
|
||||
} as unknown as ServiceWorkerRegistration;
|
||||
const controller = createServiceWorkerPageController({
|
||||
container: {
|
||||
controller: null,
|
||||
register: vi.fn(),
|
||||
getRegistration: vi.fn(async () => foreign),
|
||||
addEventListener: vi.fn(),
|
||||
removeEventListener: vi.fn(),
|
||||
} as never,
|
||||
routerBasePath: "/",
|
||||
origin: ORIGIN,
|
||||
selection: {
|
||||
mode: "REMOVE_REGISTRATION",
|
||||
scriptPath: "service-worker.js",
|
||||
handlers: [],
|
||||
},
|
||||
} as never);
|
||||
|
||||
await expect(controller.start()).resolves.toMatchObject({
|
||||
kind: "INCOMPATIBLE",
|
||||
});
|
||||
expect(foreign.unregister).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
});
|
||||
|
||||
describe("service worker page protocol", () => {
|
||||
it("does not attach late listeners when stopped during registration", async () => {
|
||||
const browser = pageContainer();
|
||||
|
||||
Reference in New Issue
Block a user