Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Select an option

  • Save marcusramberg/32278b2c46371e85bbe1f39a45bcfc08 to your computer and use it in GitHub Desktop.

Select an option

Save marcusramberg/32278b2c46371e85bbe1f39a45bcfc08 to your computer and use it in GitHub Desktop.
# NixOS driver test proving the desktop app opens external login URLs in the
# system browser instead of navigating in-app.
#
# The real flow is: the remote web login page calls
# `window.electronBridge.openExternalLogin(url)` (exposed by the preload
# script), which invokes the `auth:open-external-login` IPC handler in the main
# process, which calls Electron's `shell.openExternal()`. On Linux that shells
# out to `xdg-open`.
#
# This test serves an entrypoint page that immediately calls
# `openExternalLogin(...)` on load (mirroring the web login page), and installs a
# fake `xdg-open` that records the URL it was asked to open. Seeing the URL
# recorded proves the whole preload -> IPC -> shell.openExternal path works and
# that login opens an external browser.
#
# Build the bundle pointing at the VM entrypoint first:
# DESKTOP_ENTRYPOINT_URL=http://localhost:8080 NODE_ENV=production \
# pnpm --filter=desktop exec electron-vite build
{
pkgs,
desktopApp ? import ./desktop-app.nix { inherit pkgs; },
entrypointPort ? 8080,
}:
let
loginUrl = "https://auth.example.com/authorize?client_id=test&state=xyz";
# Entrypoint page that behaves like the web login page inside the wrapper:
# as soon as the bridge is available it asks the app to open the external
# browser login.
indexHtml = pkgs.writeText "index.html" ''
<!doctype html>
<html>
<head><meta charset="utf-8" /><title>login</title></head>
<body>
<script>
if (window.electronBridge && window.electronBridge.openExternalLogin) {
window.electronBridge.openExternalLogin(${builtins.toJSON loginUrl});
}
</script>
</body>
</html>
'';
webroot = pkgs.runCommand "remarkable-desktop-login-webroot" { } ''
mkdir -p $out
cp ${indexHtml} $out/index.html
'';
# Stand-in for a browser: records whatever URL Electron's shell.openExternal
# hands to it, then exits. Placed on PATH so `xdg-open` resolves to this.
fakeXdgOpen = pkgs.writeShellScriptBin "xdg-open" ''
printf '%s\n' "$1" >> /tmp/xdg-open.log
'';
in
pkgs.testers.runNixOSTest {
name = "remarkable-desktop-external-login";
nodes.machine =
{ ... }:
{
imports = [
(pkgs.path + "/nixos/tests/common/x11.nix")
];
services.static-web-server = {
enable = true;
listen = "[::]:${toString entrypointPort}";
root = webroot;
};
# The fake xdg-open must come before any real one on PATH.
environment.systemPackages = [
fakeXdgOpen
desktopApp
];
virtualisation.memorySize = 2048;
virtualisation.cores = 2;
};
testScript = ''
start_all()
machine.wait_for_unit("static-web-server.service")
machine.wait_for_open_port(${toString entrypointPort})
machine.wait_for_x()
machine.succeed("remarkable-desktop >&2 &")
# The login page auto-triggers openExternalLogin, which routes through the
# main process to shell.openExternal -> xdg-open. Wait for our fake browser
# to be invoked and assert it received the exact login URL.
machine.wait_until_succeeds("test -s /tmp/xdg-open.log", timeout=60)
machine.succeed("grep -qF ${pkgs.lib.escapeShellArg loginUrl} /tmp/xdg-open.log")
'';
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment