Skip to content

@fkn/lib/attach-policy

type FrameFetchClassifier = "no-base" | "fetchTarget";

How a fetch url is read. 'no-base' is new URL(url), which accepts the base-dependent forms https:h/x and http:h/x as if they named h. 'fetchTarget' is the shared classifier, which calls those relative and refuses them. The middle page keeps 'no-base' until the contract deploy, so an application on an older library is refused nothing new; the library’s own gate passes 'fetchTarget'.


type FrameFetchPolicy = object;
approvedOrigins: ReadonlySet<string>;

exact origins this attachment has legitimately visited: the attach url plus every goto target

declaredHosts: string[];

bare hostnames the app declared at attach; matched on hostname alone, any scheme or port

session: string;

” means the shared render-proxy jar; non-empty is an isolated per-attach session


type FrameFetchVerdict =
| {
kind: "refuse";
reason: string;
}
| {
kind: "consent";
promptHosts: string[];
targetHost: string;
};
function frameFetchVerdict(
policy,
url,
__namedParameters?): FrameFetchVerdict;

FrameFetchPolicy

unknown

FrameFetchClassifier = 'no-base'

FrameFetchVerdict