fix(webview): route webview:changed only to its owner in multi-user mode

webview:changed carried only {action, id} and the SSE routing hint had no
webview: branch, so every connected client received it: in multi-user mode
any user saw the ids of other users' web-tab creates, edits and deletes.
The event now carries the web tab's owner (from the stored record) and is
routed to that owner plus admins. Single-user delivery is unchanged.
This commit is contained in:
Aamer Akhter
2026-09-26 22:45:35 -04:00
parent 45ea2e1d32
commit e71971cab4
5 changed files with 249 additions and 5 deletions
+7
View File
@@ -96,6 +96,7 @@ import { PushSubscriptionStore } from '../push-store.js';
import webpush from 'web-push';
import { SseStreamManager } from './sse-stream-manager.js';
import { deriveTabLayoutSseHint } from './tab-layout-sse.js';
import { deriveWebviewSseHint } from './webview-sse.js';
import {
type SessionListenerRefs,
createSessionListeners,
@@ -2461,6 +2462,12 @@ export class WebServer extends EventEmitter {
if (event.startsWith('tab:')) {
return deriveTabLayoutSseHint(data);
}
// Saved-webview invalidations carry the trusted resource owner. Route them to
// that owner (plus admins), so an admin editing a user's web tab notifies the
// user, and no other user learns the ids of someone else's web tabs.
if (event.startsWith('webview:')) {
return deriveWebviewSseHint(data);
}
// Session-scoped families: resolve the owner from the payload's session id.
const SESSION_PREFIXES = [
'session:',