Skip to content

Fix postMessage_ when Safari empties document.referrer - #117

Open
marco-n-dream wants to merge 2 commits into
masterfrom
marco/safari-empty-referrer-postmessage
Open

marco-n-dream wants to merge 2 commits into
masterfrom
marco/safari-empty-referrer-postmessage

Conversation

@marco-n-dream

@marco-n-dream marco-n-dream commented Oct 7, 2026 •

Copy link
Copy Markdown

Safari's privacy protections return an empty document.referrer in sandboxed or cross-site game frames (WebKit Document::referrerForBindings). postMessage_ passes it as targetOrigin, so postMessage throws, the game's ready never reaches the screen, and the screen stays on its loader. Seen on a Safari screen with a custom-URL game served with a CSP sandbox header.

  • postMessage_ in airconsole-1.11.0.js (in place), beta/airconsole-1.12.0.js and deprecated/airconsole-1.7.0.js to 1.10.0: with an empty referrer it targets location.ancestorOrigins[0], the parent's origin; without one, "" keeps the old throw-and-log path.
  • New spec loads the runner's bundle in a sandboxed frame with an empty referrer and expects ready at the parent; it runs in the 1.11.0 and 1.12.0 runners.

Testing: npx playwright test --project Chromium 7/7 passed, locally and in CI; with the two bundle changes reverted the new spec fails in both runners; both runners pass in Playwright WebKit.
Out of scope: bumping the airconsole-api submodule in airconsole-appengine, which is what serves these files.

Safari's privacy protections return an empty document.referrer when the
referrer's site differs from the frame's origin, as in sandboxed or
cross-site game frames. postMessage(data, "") throws, so 'ready' never
reached the platform and the screen stayed on its loader. Fall back to
the parent's origin from location.ancestorOrigins; without one, keep the
old throw-and-log path.
@marc-n-dream

marc-n-dream commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Technically LGTM but 2 points need to be addressed

  1. This change should be applied from airconsole-1.7.0.js up to airconsole-1.12.0.js with test coverage in 1.11.0+ with a ticket for me to address it. We need to realign the tests to be more in line with how the testing in airconsole-1.2.0 and before worked with the stacking of test cases.
  2. while out of scope we should also consider a follow up for the airconsole ads update as that is being used by the platform for ads and the store.

And note: if this is merged, it requires the next airconsole-appengine to update the submodule. normally the one updating the api has to take care of that as no PR can be merged without adopting the update to api (git submodules master up to date requirement)

Same change as 03a562c for the deprecated bundles that games still load. They get no spec; coverage stays on 1.11.0 and later.
@marco-n-dream

Copy link
Copy Markdown
Author

Thanks Marc.

  1. Applied the same change to 1.7.0 to 1.10.0 (86e79ce); the new spec stays on 1.11.0+. Test realignment: ENG-3425, assigned to you.
  2. Ads follow-up: ENG-3426, assigned to you. The platform's own ad pages load same-origin and unsandboxed, so I found no production path that hits it yet; it reproduces with a sandboxed frame.
  3. Agreed: I'll open the airconsole-appengine submodule bump as soon as this is merged.

@marc-n-dream marc-n-dream left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants