Created
August 12, 2026 11:11
-
-
Save marcusramberg/32278b2c46371e85bbe1f39a45bcfc08 to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # NixOS driver test proving the desktop app opens external login URLs in the | |
| # system browser instead of navigating in-app. | |
| # | |
| # The real flow is: the remote web login page calls | |
| # `window.electronBridge.openExternalLogin(url)` (exposed by the preload | |
| # script), which invokes the `auth:open-external-login` IPC handler in the main | |
| # process, which calls Electron's `shell.openExternal()`. On Linux that shells | |
| # out to `xdg-open`. | |
| # | |
| # This test serves an entrypoint page that immediately calls | |
| # `openExternalLogin(...)` on load (mirroring the web login page), and installs a | |
| # fake `xdg-open` that records the URL it was asked to open. Seeing the URL | |
| # recorded proves the whole preload -> IPC -> shell.openExternal path works and | |
| # that login opens an external browser. | |
| # | |
| # Build the bundle pointing at the VM entrypoint first: | |
| # DESKTOP_ENTRYPOINT_URL=http://localhost:8080 NODE_ENV=production \ | |
| # pnpm --filter=desktop exec electron-vite build | |
| { | |
| pkgs, | |
| desktopApp ? import ./desktop-app.nix { inherit pkgs; }, | |
| entrypointPort ? 8080, | |
| }: | |
| let | |
| loginUrl = "https://auth.example.com/authorize?client_id=test&state=xyz"; | |
| # Entrypoint page that behaves like the web login page inside the wrapper: | |
| # as soon as the bridge is available it asks the app to open the external | |
| # browser login. | |
| indexHtml = pkgs.writeText "index.html" '' | |
| <!doctype html> | |
| <html> | |
| <head><meta charset="utf-8" /><title>login</title></head> | |
| <body> | |
| <script> | |
| if (window.electronBridge && window.electronBridge.openExternalLogin) { | |
| window.electronBridge.openExternalLogin(${builtins.toJSON loginUrl}); | |
| } | |
| </script> | |
| </body> | |
| </html> | |
| ''; | |
| webroot = pkgs.runCommand "remarkable-desktop-login-webroot" { } '' | |
| mkdir -p $out | |
| cp ${indexHtml} $out/index.html | |
| ''; | |
| # Stand-in for a browser: records whatever URL Electron's shell.openExternal | |
| # hands to it, then exits. Placed on PATH so `xdg-open` resolves to this. | |
| fakeXdgOpen = pkgs.writeShellScriptBin "xdg-open" '' | |
| printf '%s\n' "$1" >> /tmp/xdg-open.log | |
| ''; | |
| in | |
| pkgs.testers.runNixOSTest { | |
| name = "remarkable-desktop-external-login"; | |
| nodes.machine = | |
| { ... }: | |
| { | |
| imports = [ | |
| (pkgs.path + "/nixos/tests/common/x11.nix") | |
| ]; | |
| services.static-web-server = { | |
| enable = true; | |
| listen = "[::]:${toString entrypointPort}"; | |
| root = webroot; | |
| }; | |
| # The fake xdg-open must come before any real one on PATH. | |
| environment.systemPackages = [ | |
| fakeXdgOpen | |
| desktopApp | |
| ]; | |
| virtualisation.memorySize = 2048; | |
| virtualisation.cores = 2; | |
| }; | |
| testScript = '' | |
| start_all() | |
| machine.wait_for_unit("static-web-server.service") | |
| machine.wait_for_open_port(${toString entrypointPort}) | |
| machine.wait_for_x() | |
| machine.succeed("remarkable-desktop >&2 &") | |
| # The login page auto-triggers openExternalLogin, which routes through the | |
| # main process to shell.openExternal -> xdg-open. Wait for our fake browser | |
| # to be invoked and assert it received the exact login URL. | |
| machine.wait_until_succeeds("test -s /tmp/xdg-open.log", timeout=60) | |
| machine.succeed("grep -qF ${pkgs.lib.escapeShellArg loginUrl} /tmp/xdg-open.log") | |
| ''; | |
| } |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment