Skip to content

Commit f3d87cc

Browse files
committed
Route only logs/stream rather than the whole logs subresource
Narrows the default prefix so a future logs read served by the control plane is not swept onto the browser VM.
1 parent 5386bab commit f3d87cc

2 files changed

Lines changed: 41 additions & 3 deletions

File tree

‎src/lib/browser-routing.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ const DEFAULT_BROWSER_ROUTING_SUBRESOURCES = [
4848
'playwright',
4949
'process',
5050
'fs',
51-
'logs',
51+
'logs/stream',
5252
];
5353
const BROWSER_ROUTE_CACHEABLE_PATH = /^\/(?:v\d+\/)?browsers(?:\/[^/]+)?\/?$/;
5454
const BROWSER_POOL_ACQUIRE_PATH = /^\/(?:v\d+\/)?browser_pools\/[^/]+\/acquire\/?$/;

‎tests/lib/browser-routing.test.ts‎

Lines changed: 40 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -455,13 +455,13 @@ describe('browser routing', () => {
455455
'playwright',
456456
'process',
457457
'fs',
458-
'logs',
458+
'logs/stream',
459459
]);
460460
});
461461
});
462462

463463
test('allowlist matching is segment-boundary aware (telemetry/events stays on the control plane)', () => {
464-
const prefixes = ['curl', 'telemetry/stream', 'computer', 'playwright', 'process', 'fs', 'logs'];
464+
const prefixes = ['curl', 'telemetry/stream', 'computer', 'playwright', 'process', 'fs', 'logs/stream'];
465465
expect(matchesDirectVMPrefix('telemetry/stream', prefixes)).toBe(true);
466466
expect(matchesDirectVMPrefix('telemetry/stream/x', prefixes)).toBe(true);
467467
expect(matchesDirectVMPrefix('telemetry/events', prefixes)).toBe(false);
@@ -476,6 +476,9 @@ describe('browser routing', () => {
476476
expect(matchesDirectVMPrefix('fs/watch/watch-1/events', prefixes)).toBe(true);
477477
expect(matchesDirectVMPrefix('fsx/read_file', prefixes)).toBe(false);
478478
expect(matchesDirectVMPrefix('logs/stream', prefixes)).toBe(true);
479+
expect(matchesDirectVMPrefix('logs/stream/x', prefixes)).toBe(true);
480+
expect(matchesDirectVMPrefix('logs', prefixes)).toBe(false);
481+
expect(matchesDirectVMPrefix('logs/history', prefixes)).toBe(false);
479482
expect(matchesDirectVMPrefix('logstream', prefixes)).toBe(false);
480483
expect(matchesDirectVMPrefix('extensions', prefixes)).toBe(false);
481484
expect(matchesDirectVMPrefix('replays/rec-1', prefixes)).toBe(false);
@@ -1058,4 +1061,39 @@ describe('browser routing', () => {
10581061
]);
10591062
});
10601063
});
1064+
1065+
test('routes only logs/stream, not the logs subresource', async () => {
1066+
await withBrowserRoutingEnv(undefined, async () => {
1067+
const cache = new BrowserRouteCache();
1068+
cache.set({
1069+
sessionId: 'sess-1',
1070+
baseURL: 'http://browser-session.test/browser/kernel',
1071+
jwt: 'token-abc',
1072+
});
1073+
1074+
const routed: string[] = [];
1075+
const wrappedFetch = createRoutingFetch(
1076+
async (input) => {
1077+
routed.push(normalizeURL(input));
1078+
return new Response(null, { status: 204 });
1079+
},
1080+
{
1081+
apiBaseURL: 'https://api.example/',
1082+
subresources: browserRoutingSubresourcesFromEnv(),
1083+
cache,
1084+
},
1085+
);
1086+
1087+
for (const path of ['logs/stream', 'logs', 'logs/history', 'logstream']) {
1088+
await wrappedFetch(`https://api.example/browsers/sess-1/${path}`);
1089+
}
1090+
1091+
expect(routed).toEqual([
1092+
'http://browser-session.test/browser/kernel/logs/stream?jwt=token-abc',
1093+
'https://api.example/browsers/sess-1/logs',
1094+
'https://api.example/browsers/sess-1/logs/history',
1095+
'https://api.example/browsers/sess-1/logstream',
1096+
]);
1097+
});
1098+
});
10611099
});

0 commit comments

Comments
 (0)