Run VSP HTTP requests on the main process. - #4040
Open
jholdstock wants to merge 1 commit into
Open
Conversation
Previously VSP HTTP requests were executed on the renderer process. This is not good practice for electron apps beause this blocks the UI while the request is in progress. It also causes a Sec-Fetch-Site header to be added to the request because it is handled in the same way as a real Chromium browser. This has become problematic since vspd now implements CSRF protection which inspects the Sec-Fetch-Site header. Subsequently the "Fetch VSP Ticket Status" button on the "Staking" > "Ticket Status" tab is now broken. Fortunately this is the only request made by Decrediton which is subject to CSRF protection (everything else goes through dcrwallet) so all other functionality is working. Ticket purchases, voting etc are unaffected. This PR moves the HTTP requests to the main process using the same pattern already used for daemon/dcrlnd/dex/trezord requests. VSP HTTP requests are registered as handlers in main.development.js, and used by wallet/vsp.js by calling invoke(...) instead of via middleware.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previously VSP HTTP requests were executed on the renderer process. This is not good practice for electron apps beause this blocks the UI while the request is in progress. It also causes a
Sec-Fetch-Siteheader to be added to the request because it is handled in the same way as a real Chromium browser.This has become problematic since vspd now implements CSRF protection which inspects the
Sec-Fetch-Siteheader. Subsequently the "Fetch VSP Ticket Status" button on the "Staking" > "Ticket Status" tab is now broken. Fortunately this is the only request made by Decrediton which is subject to CSRF protection (everything else goes through dcrwallet) so all other functionality is working. Ticket purchases, voting etc are unaffected.This PR moves the HTTP requests to the main process using the same pattern already used for daemon/dcrlnd/dex/trezord requests. VSP HTTP requests are registered as handlers in
main.development.js, and used bywallet/vsp.jsby callinginvoke(...)instead of via middleware.