fix: route every host-browser open through open_url_external

The Rust command existed but nothing called it. All four frontend call
sites still used `openUrl` from `@tauri-apps/plugin-opener`, so the
environment fix was inert and the three dialogs carried the same Linux bug
as the terminal: DockerInstallDialog's docs link, ClaudeAuthModal's sign-in
link and UpdateDialog's release link would all have reported success while
launching nothing.

`openUrlExternal` in tauri-commands.ts is now the single sink. There is no
platform branch: Linux gets the sanitized spawn, macOS and Windows reach
the same plugin as before but from Rust, and every platform picks up the
Rust-side re-validation, which matters because these URLs originate in an
untrusted container.

Comments in urlRelay.ts and urlDetector.ts that named `openUrl` as the sink
they guard are updated to match, and the two test files that mocked
`@tauri-apps/plugin-opener` now mock the command instead.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-09-17 10:09:57 -07:00
co-authored by Claude Opus 5
parent 9297020688
commit 5a09254538
9 changed files with 46 additions and 33 deletions
+15
View File
@@ -398,3 +398,18 @@ export const rollbackMigration = (projectId: string) =>
* app crash shows up here as phase "interrupted". */
export const getMigrationState = (projectId: string) =>
invoke<MigrationState | null>("get_migration_state", { projectId });
/** Open a URL in the user's own browser.
*
* Replaces `openUrl` from `@tauri-apps/plugin-opener` at every call site. On
* Linux the app ships as an AppImage whose environment leaks into everything
* it spawns, which kills a *cold-launched* browser before it paints while
* `xdg-open` still exits 0 — so the plugin path reported success and did
* nothing (triple-c#34). The Rust side hands the child a repaired environment
* and re-validates the URL, which matters because these URLs originate in an
* untrusted container. macOS and Windows still reach the plugin, just from
* Rust, so there is no platform branch here.
*
* Rejects with a string already phrased for a toast. */
export const openUrlExternal = (url: string) =>
invoke<void>("open_url_external", { url });