Conversation
Adds a shared getPreviewProxyDetails/toPreviewProxyUrl/ensurePreviewProxySession helper in blocks/shared/preview-proxy.js and routes da-library, da-prepare, canvas prepare-menu, ew-panel-extensions, and ew-tool-panel plugin/extension URLs through it. livePreviewLogin now takes a 4th getUrl param so the /gimme_cookie request always targets the same origin the iframe/popup loads, fixing a mismatch where canvas surfaces could authenticate against the prod preview origin while the iframe loaded from stage-preview (or vice versa). Adds unit coverage for preview-proxy.js (including ensurePreviewProxySession), the getUrl branch of getLivePreviewUrl/livePreviewLogin, and a same-origin assertion at each canvas/edit call site. Assisted-by: GitHub Copilot
|
Hello, I'm the AEM Code Sync Bot and I will run some actions to deploy your branch.
|
Cross-org plugin URLs are left unchanged so public plugins hosted by another org keep working and no gimme_cookie is requested for orgs the user may not belong to. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Importing editor-utils.js from the prepare menu, tool panel and extension panels pulled toolbar-controller into their module graphs, which changed toolbar render timing and broke canvas tests in CI. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
shsteimer
marked this pull request as ready for review
September 28, 2026 17:27
Window-experience plugins open in a new tab where sidekick handles auth, so skip the preview proxy and gimme_cookie for them. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
ew-selection-toolbar.hide() calls close() on every nx-menu. The fixture had no close(), so any toolbar render that landed during a canvas test threw, which failed CI intermittently (including on main). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The CI failure was the nx-menu fixture, not the import graph, so the separate preview-origin.js module isn't needed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
shsteimer
commented
Sep 28, 2026
| @@ -1,4 +1,12 @@ | |||
| class NxMenu extends HTMLElement {} | |||
| class NxMenu extends HTMLElement { | |||
| open = false; | |||
Contributor
Author
There was a problem hiding this comment.
this test fixture change isn't stricly related, but prevents intermittent failures on TypeError: m.close is not a function
Other CI runs that failed with the same error:
• main: https://github.com/adobe/da-live/actions/runs/35979776106
• main: https://github.com/adobe/da-live/actions/runs/35972047005
• imgswap PR: https://github.com/adobe/da-live/actions/runs/35888552143
3 of 5 tasks
mhaack
reviewed
Sep 30, 2026
| import { getLivePreviewUrl } from './constants.js'; | ||
| import { livePreviewLogin } from './utils.js'; | ||
|
|
||
| const AEM_HOST = /\.(aem|hlx)\.(page|live)$/; |
Contributor
There was a problem hiding this comment.
Think we should not have hlx here any more aem is fine.
5 of 10 tasks
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds
blocks/shared/preview-proxy.js(getPreviewProxyDetails/toPreviewProxyUrl/ensurePreviewProxySession), which rewrites plugin URLs (relative paths,*.aem|hlx.page|live,content.da.live,admin.da.live) to the DA preview proxy (branch--site--org.preview.da.live) and requests/gimme_cookiefor that origin before the plugin loads. Non-OOTB plugin sources and icons in da-library, da-prepare, canvas prepare-menu, and ew-panel-extensions go through it.Only same-org plugins are proxied: callers pass
currentOrg, and URLs for another org stay unchanged, so public cross-org plugins keep working and no cookie is requested for orgs the user may not belong to.window-experience plugins are not proxied: they open at their original URL in a new tab, and the user authenticates with sidekick as before.getLivePreviewUrl/livePreviewLogintake abranch(was hardcodedmain), andlivePreviewLogintakes agetUrlso canvas surfaces authenticate against the same origin (getPreviewOrigin) their iframe/popup loads.livePreviewLoginskips the request when there's no IMS token.Motivation and Context
Library and Prepare menu extensions are iframed, but for protected sites, these iframes could lead to 401s. This was changed for apps adobe/da-nx#618 and for block library pages #1372, but not for plugins.
Warning
This will merge conflict with #1372
If this merges first, that should be updated to use the new shared preview-proxy module. If that merges first, then I can make that change here when fixing the conflict.
How Has This Been Tested?
Unit tests added for
preview-proxy.js(includingensurePreviewProxySession), thegetUrlbranch ofgetLivePreviewUrl/livePreviewLogin, and a same-origin assertion at each canvas/edit call site. Full affected suite passes, lint clean.fully tested on both
https://plugprox--da-live--adobe.aem.live/canvas#/shsteimer/da-playground/index
https://plugprox--da-live--adobe.aem.live/edit#/shsteimer/da-playground/index
before

after:
Types of changes
Checklist: