@fkn/lib/attach-policy
Type Aliases
Section titled “Type Aliases”FrameFetchClassifier
Section titled “FrameFetchClassifier”type FrameFetchClassifier = "no-base" | "fetchTarget";How a fetch url is read. 'no-base' is new URL(url), which accepts the base-dependent forms
https:h/x and http:h/x as if they named h. 'fetchTarget' is the shared classifier, which
calls those relative and refuses them. The middle page keeps 'no-base' until the contract deploy,
so an application on an older library is refused nothing new; the library’s own gate passes
'fetchTarget'.
FrameFetchPolicy
Section titled “FrameFetchPolicy”type FrameFetchPolicy = object;Properties
Section titled “Properties”approvedOrigins
Section titled “approvedOrigins”approvedOrigins: ReadonlySet<string>;exact origins this attachment has legitimately visited: the attach url plus every goto target
declaredHosts
Section titled “declaredHosts”declaredHosts: string[];bare hostnames the app declared at attach; matched on hostname alone, any scheme or port
session
Section titled “session”session: string;” means the shared render-proxy jar; non-empty is an isolated per-attach session
FrameFetchVerdict
Section titled “FrameFetchVerdict”type FrameFetchVerdict = | { kind: "refuse"; reason: string;} | { kind: "consent"; promptHosts: string[]; targetHost: string;};Functions
Section titled “Functions”frameFetchVerdict()
Section titled “frameFetchVerdict()”function frameFetchVerdict( policy, url, __namedParameters?): FrameFetchVerdict;Parameters
Section titled “Parameters”policy
Section titled “policy”unknown
__namedParameters?
Section titled “__namedParameters?”classifier?
Section titled “classifier?”FrameFetchClassifier = 'no-base'