Repository navigation
Conversation
The ew block library loaded content and previews directly from aem.page/aem.live, which returns a 401 on protected sites when the user isn't authenticated via sidekick (issue #1201). Route library sources, variant HTML, and the preview iframe through the DA Preview Proxy (preview.da.live) instead, using the canvas editor's existing getPreviewOrigin. The proxy authenticates with the editor's DA session cookie, so signed-in DA users no longer hit a 401. Proxy fetches send credentials, and loadBlockLibrary defensively ensures the gimme_cookie session before fetching. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Follow-up review fixes for routing the library through the DA Preview Proxy: - Send credentials only to the proxy. aem.page/aem.live answer with `Access-Control-Allow-Origin: *`, so credentialed requests to absolute library sources that aren't proxied failed CORS and the library came back empty. Absolute `branch--site--org.aem.*`/`hlx.*` sources are now rewritten through the proxy too (query and hash preserved; look-alike hosts untouched). - Mint the proxy session cookie (memoized per org/site/branch) before every proxied request, not just in loadBlockLibrary: the side panel, option/editor sheets and template insertion now get it too, for the actual branch. - Wait for that cookie before pointing the preview iframe at the proxy (new ensureItemPreviewAccess, used by the panel and the modal). - Route insertTemplate through the proxy. - Resolve inserted variant images against the public AEM origin again, so saved content never points at the auth-only proxy. - When every library source answers 401/403, flag `authError` (not cached) and show an actionable "sign in with AEM Sidekick" message instead of "No blocks found". Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
The PR #1385 highlights that this will conflict with this PR. I was initially suggesting to merge this 1372 (this PR) first, then have 1385 refactor the changes we merged here here. However, I noticed that 1385 covers one case this PR doesn't:
@dicagno could you please port the shared preview-proxy module to this PR 1372, check that that fixes the case I found in this comment, and work with @shsteimer to check that it was implemented correctly here? |
|
@dicagno if it's easier than porting that module here and you'd like to just apply your changes directly to the branch I have for #1385, |
Description
Routes the canvas ("ew") block library through the DA Preview Proxy (
preview.da.live) instead of loading content and previews directly fromaem.page/aem.live.Changes in
blocks/canvas/ew-panel-extensions/helpers.js:calculateSources) are now built fromgetPreviewOrigin(org, site, ref)rather than…aem.live.getBlockVariants) rewrites AEM-hosted block URLs (ref--site--org.aem.page|live) to the proxy host before fetching (newtoPreviewProxyUrlhelper).getItemPreviewUrl) points at the proxy host.credentials: 'include'so the session cookie is transmitted.loadBlockLibrarydefensively callsfetchWysiwygCookieto ensure the proxy'sgimme_cookiesession exists before fetching (the canvas editor already prefetches this on doc load; this covers the case where the library is the first thing to hit the proxy).Reuses the canvas editor's existing
getPreviewOrigin/fetchWysiwygCookie— no new eventing or auth mechanism introduced.Related Issue
Fixes #1201
Motivation and Context
On protected (Helix-authenticated) sites, the block library fetched content straight from
aem.page/aem.live, which returns a generic 401 when the user isn't authenticated via sidekick. Loading through the DA Preview Proxy lets the request authenticate with the user's existing DA session instead, so a signed-in DA user never sees the 401 — the token-exchange approach suggested in the issue. This mirrors the fix already applied to top-level apps in adobe/da-nx#618.How Has This Been Tested?
DA Preview Proxy routingsuite locking in that (1) the preview iframe URL, (2) AEM-hosted variant HTML fetches, and (3) configured library sources all route through the proxy host (neveraem.page/aem.live) and send credentials. Full suite:npm test— the ew-panel-extensions suite passes 38/38; lint clean.…stage-preview.da.live(notaem.page/aem.live), return 200, and send cookies, andgimme_cookiefires. Further tests might be performed against protected sites.Test URL:
https://libproxy--da-live--adobe.aem.live/
Types of changes
Checklist: