Commit Graph
7898 Commits
Author SHA1 Message Date
Karl Seguin 1dd33ee7ec Merge pull request #3604 from lightpanda-io/sanitizer
webapi: Start of Sanitizer WebAPI
2026-09-23 21:23:20 +08:00
Karl Seguin d070a0d34e Merge pull request #3605 from lightpanda-io/x-frame-options
http: add support for x-frame-options
2026-09-23 19:04:08 +08:00
Karl Seguin 1bc6bcc3d1 dedupe close path 2026-09-23 17:08:03 +08:00
Scott Taylor 1296861350 cdp: notify target closure when disposing browser contexts 2026-09-23 16:33:17 +08:00
Karl Seguin 414167bfcd Merge pull request #3602 from lightpanda-io/iterative-rendertree
mem: make markdown/screenshot iterative
2026-09-23 15:15:37 +08:00
Karl Seguin 80640f7204 http: add support for x-frame-options
Brings /x-frame-options/ from 43/157 to  157/157.
2026-09-23 12:54:19 +08:00
Karl Seguin 628248a51c webapi: Start of Sanitizer WebAPI
This is the configuration-half of the Sanitizer API. In a follow up, we'll add
the missing element.setHtml and sanitizer option to the existing setHTMLUnsafe
(as well as the ShadowRoot and Document sanitizer-aware methods).
2026-09-23 12:38:43 +08:00
Karl Seguin 31198445dd Merge pull request #3598 from cdebled/cdp-blank-lifecycle
cdp: report the initial about:blank as loaded to lifecycle events
2026-09-23 11:56:18 +08:00
Karl Seguin 36f2a6cb96 more rebase + regenerate 2026-09-23 11:20:42 +08:00
Karl Seguin 71cc6f93e5 fix robots log message length 2026-09-23 11:20:42 +08:00
Adrià Arrufat 728f61a80d log: check the message rules at comptime
logToErased asserts that a log message is at most 30 characters of
plain text, but only in a debug build and only once the line actually
runs. A message on a rare path therefore ships fine and then panics on
whoever first reaches it: `serve --host 0.0.0.0` without
--advertise-host crashed on startup in every debug build, because
"advertising loopback for wildcard bind" is 38 characters.

Every message is a literal, so make the six wrappers take a comptime
msg and apply the same two rules through @compileError. The runtime
check stays as the backstop for the paths the compiler does not
analyse for the current target, and now reads the same constant.

Eleven messages were over the limit; shorten them. The detail already
lives in the kv pairs in each case. renderFailed takes its message as
comptime now, the only call site that passed a runtime one.

Note the check only covers code analysed for the target being built:
the two in Certificates.zig sit in an OS switch prong that Linux never
compiles, and were found by scanning the source rather than by the
compiler.
2026-09-23 11:20:42 +08:00
Karl Seguin 11e1505cd7 Merge pull request #3547 from lightpanda-io/navigation-reload
`Navigation.reload`
2026-09-23 08:02:29 +08:00
Karl Seguin 4a7590691d Merge pull request #3546 from lightpanda-io/robots-limit-entries
Robot Limit Entries
2026-09-23 07:31:30 +08:00
Karl Seguin e1aec431d4 Merge pull request #3588 from lightpanda-io/scroll-clamp-chain
Clamp scroll offsets, and latch a wheel to one scroll container
2026-09-23 06:47:17 +08:00
Karl Seguin 074965c046 mem: make markdown/screenshot iterative
Follow up to https://github.com/lightpanda-io/browser/pull/3573. Both markdown
and scerenshot stackoverflow sooner than dump due to their larger stack frames.
2026-09-23 06:41:15 +08:00
Karl Seguin e27270cde3 Merge pull request #3594 from lightpanda-io/webdriver-execute
webdriver: execute
2026-09-23 06:05:57 +08:00
Muki Kiboigo 8682cca571 remove inaccurate Robots comment 2026-09-22 12:55:27 -07:00
Muki Kiboigo be60d51990 add caching option for settle in RobotsGate 2026-09-22 12:55:27 -07:00
Muki Kiboigo d16091a403 0 for robot entry limit means no limit 2026-09-22 12:55:26 -07:00
Muki Kiboigo 7335c752ba pass errors up to Caller in navigation event dispatch 2026-09-22 12:49:42 -07:00
Celine Debled 431e41f865 cdp: report the initial about:blank as loaded to lifecycle events 2026-09-22 16:47:47 +02:00
Adrià Arrufat 93c551bed6 css: share the axis shorthand table with the CSSOM
The cascade expanded overscroll-behavior into longhands but
CSSStyleDeclaration didn't, so setting the shorthand left
overscrollBehaviorX reading empty and a style= block round-tripped
through the object lost it.

CssParser.axis_shorthands is now the one list, with axisShorthand and
axisLonghand as the lookups both sides use: the CSSOM's overflow-only
special cases (set, apply, remove, priority, serialize) became that
lookup, and OverflowPair became AxisPair. Verified against Chrome 153:
`overscroll-behavior: contain auto` reads back per axis, collapses to
`contain` when both match, and serializes as one declaration.
2026-09-22 16:39:13 +02:00
Adrià Arrufat fdee7d558c scroll: write first, then report whether it moved
writeScroll held the map entry across the clamp, which reads styles and
walks children, and it created an entry even for a write that changed
nothing. It now clamps both axes against a plain lookup and only takes
the entry when an offset actually moves.

That makes the write itself the answer to "can this container move?", so
the wheel walk asks by writing instead of recomputing the extent first,
and canScrollAxis is gone.
2026-09-22 16:39:13 +02:00
Karl Seguin d873e1bd7b Merge pull request #3595 from cdebled/cdp-reply-session-id
cdp: echo the sessionId in replies to browser-level commands
2026-09-22 20:11:07 +08:00
Celine Debled ce5f6195db cdp: test that replies echo the sessionId 2026-09-22 12:28:37 +02:00
Celine Debled c98afa4beb cdp: echo the sessionId in replies to browser-level commands 2026-09-22 12:28:37 +02:00
Karl Seguin bbd99f47e8 webdriver: execute
Adds the ability to execute JavaScript via WebDriver. The other webdriver
endpoints were able to re-use the existing BiDi code (e.g. navigating via
webdriver or bidi quickly ends up in the same function). But for execute, it's
completely different, from input parameters, to running the code, to the result
that's returned. So there's a dedicated handler for this: `execute.zig`. But
the rest of the infrastructure (the http waiting for a reply, the routing, the
parameter parsing, ... are all the same).
2026-09-22 16:31:52 +08:00
Karl Seguin b84e5b7397 Merge pull request #3591 from lightpanda-io/dont-reuse-bad-connections
http: dont' re-use connections which are likely in a bad state.
2026-09-22 15:43:30 +08:00
Karl Seguin 239a7937e0 Merge pull request #3592 from lightpanda-io/element-focus
webapi: element.focus() only on focusable elements
2026-09-22 15:04:28 +08:00
Karl Seguin 92c48a68a7 Merge pull request #3534 from lightpanda-io/wasm-streaming
Implement WebAssembly.compileStreaming and instantiateStreaming
2026-09-22 14:19:52 +08:00
Adrià Arrufat 6209893a5b wasm: don't re-enter V8 when an exception is already pending
TryCatchRethrow, JsException and ExecutionTerminated all mean V8 already
has something pending: creating an error value and aborting the stream
would replace the exception the script is meant to see, or hand a killed
script a catchable Error. Drop the streaming handle instead, matching the
early exit in Caller.handleError.
2026-09-22 07:53:44 +02:00
Karl Seguin 0ffca7fa0a webapi: element.focus() only on focusable elements
Element.focus() would "focus" the element even when it shouldn't. We already
have the logic to determine if an element is focusable in `user_input.zig`, so
this was moved to Element and is now used in el.focus().
2026-09-22 11:25:52 +08:00
Karl Seguin 0b66a5ed05 http: dont' re-use connections which are likely in a bad state.
Some status-codes should never have a body except for a single trailing blank
line. If we don't handle these, then we end up with a dirty connection in our
connection pool:

1 - read the header, but not the body
2 - put the connection back in the pool
3 - try to read the header, but actually get the body from #1

WPT /fetch/api/basic/response-null-body.any.html exercises this path and is
flaky (because it depends whether the request goes back out on a keep-alive
connection)..but for a given run,you'll almost always get 1-3 failures.

This commit processes the request, but tells libcurl not to re-use the
connection.
2026-09-22 10:08:41 +08:00
Karl Seguin e96c31f157 Merge pull request #3572 from lightpanda-io/nikneym/cdp-isolated-world-origin
`cdp`: move a kept isolated-world context onto the navigated origin
2026-09-22 07:47:46 +08:00
Karl Seguin 709567e2d8 Merge pull request #3585 from lightpanda-io/webdriver-element
webdriver: add element endpoints
2026-09-22 07:47:06 +08:00
Adrià Arrufat 689045d72a user_input: latch a wheel to one scroll container
wheelScroll handed the whole delta to the nearest scroll container on
each axis, whatever state it was in, so a saturated inner scroller
trapped the wheel and the page never moved.

scrollAxis walks outward per axis and gives the whole delta to the first
container that can still move along it. A delta is never split: a
container that can only take part of it keeps the rest, and the page
moves on the next wheel. That is Chrome's rule in FindNodeToLatch
(cc/input/input_handler.cc), confirmed against Chrome 153 - one wheel of
1000px over a container with 416px of travel leaves window.scrollY at 0.

A container whose overscroll-behavior doesn't propagate takes the latch
even when it can't move, which ends the walk.
2026-09-21 17:37:26 +02:00
Adrià Arrufat e4df45a967 StyleManager: track overscroll-behavior
Chaining a wheel out of a saturated container is exactly what sites use
`overscroll-behavior: contain` to prevent, so the cascade needs to know
about it before the wheel can chain.

Two flags follow the overflow-x/overflow-y pattern: a shorthand arm in
Slots.apply covers both fold paths, and overscrollContainAxes is the
probe. `contain` and `none` both stop propagation, only `auto` lets it
through. Props was exactly full at u8.

splitOverflow serves two shorthands now, so it is splitAxisPair.
2026-09-21 17:37:26 +02:00
Adrià Arrufat 9b5434e25a scroll: clamp offsets to the scrollable extent
Every scroll write clamped at zero and nothing else, so an offset could
exceed the scrollable extent without limit and a page probing
`scrollTop >= scrollHeight - clientHeight` got a number Chrome would
never produce.

Element.scrollExtent is that bound, and setScrollTop/setScrollLeft/
scrollTo/scrollBy now share one writer that applies it. The extent is
optional and null means unbounded: without a layout engine there is no
honest box for an element sized by a stylesheet (getElementAxis reads
only inline width/height) or one holding text (contentAxis sums element
children), and refusing a scroll we can't prove impossible is worse than
allowing one too many. html and body are excluded outright, so the
viewport keeps its fabricated extent and stays unbounded.

Chrome clamps all three, so the HTML fixture asserts the limit
relationally - a real browser reserves scrollbar space in clientHeight
and lands a few px lower. The gap we keep is pinned in a Zig test
instead.

The write path also does its arithmetic in i64: the old relative path
could panic on an offset stored above maxInt(i32).
2026-09-21 17:37:26 +02:00
Muki Kiboigo 4f8536077e fix fireNavigationSuccess 2026-09-21 07:28:03 -07:00
Muki Kiboigo 8642328aa1 add navigationsuccess and navigationerror to Navigation 2026-09-21 07:26:06 -07:00
Muki Kiboigo df42a26a39 better dispatch of currententrychange event 2026-09-21 07:20:17 -07:00
Muki Kiboigo 74789d3af0 use ClockCache as the map in RobotStore 2026-09-21 07:07:08 -07:00
Karl Seguin d3262ada54 Merge pull request #3583 from lightpanda-io/improved-cache
http: improve caching
2026-09-21 21:36:47 +08:00
nikneym 238d4a53a3 cdp: move a kept isolated-world context onto the navigated origin 2026-09-21 16:28:00 +03:00
Karl Seguin dba2fdf5fc Merge pull request #3578 from lightpanda-io/response-null-body
webapi: improve fetch/response correctness with null bodies
2026-09-21 18:56:12 +08:00
Karl Seguin 6b28f986e6 Merge pull request #3586 from lightpanda-io/webdriver-http-limit
webdriver: increase http default / max limit
2026-09-21 18:55:53 +08:00
Karl Seguin 7f3cf5793f cache use s-maxcache only to reduce total cache time
Tricky since we act as both the user agent and a shared cache. This is the
safest of the two.
2026-09-21 18:52:13 +08:00
Karl Seguin ee4d54928d webdriver: increase http default / max limit
The http max default was 4K with a 16KB hard limit. The default limit is now 1MB
with an initial default of 4K. This is to accommodate larger WebDriver payloads.
2026-09-21 17:52:41 +08:00
Karl Seguin 735ae57f16 Merge pull request #3577 from lightpanda-io/type-error-helper
chore: move more cases to new typeError helper
2026-09-21 16:48:25 +08:00
Karl Seguin af47d524f2 Merge pull request #3576 from lightpanda-io/xhr-wpt
webapi: correct error on wrong method, guard headers
2026-09-21 16:08:47 +08:00