Skip to content

fix(plugins): Use preview proxy for library and prepare menu plugins. - #1385

Open
shsteimer wants to merge 10 commits into
mainfrom
plugprox
Open

shsteimer wants to merge 10 commits into
mainfrom
plugprox

Conversation

@shsteimer

@shsteimer shsteimer commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Description

Adds blocks/shared/preview-proxy.js (getPreviewProxyDetails / toPreviewProxyUrl / ensurePreviewProxySession), which rewrites plugin URLs (relative paths, *.aem|hlx.page|live, content.da.live, admin.da.live) to the DA preview proxy (branch--site--org.preview.da.live) and requests /gimme_cookie for that origin before the plugin loads. Non-OOTB plugin sources and icons in da-library, da-prepare, canvas prepare-menu, and ew-panel-extensions go through it.

Only same-org plugins are proxied: callers pass currentOrg, and URLs for another org stay unchanged, so public cross-org plugins keep working and no cookie is requested for orgs the user may not belong to.

window-experience plugins are not proxied: they open at their original URL in a new tab, and the user authenticates with sidekick as before.

getLivePreviewUrl / livePreviewLogin take a branch (was hardcoded main), and livePreviewLogin takes a getUrl so canvas surfaces authenticate against the same origin (getPreviewOrigin) their iframe/popup loads. livePreviewLogin skips the request when there's no IMS token.

Motivation and Context

Library and Prepare menu extensions are iframed, but for protected sites, these iframes could lead to 401s. This was changed for apps adobe/da-nx#618 and for block library pages #1372, but not for plugins.

Warning

This will merge conflict with #1372
If this merges first, that should be updated to use the new shared preview-proxy module. If that merges first, then I can make that change here when fixing the conflict.

How Has This Been Tested?

Unit tests added for preview-proxy.js (including ensurePreviewProxySession), the getUrl branch of getLivePreviewUrl/livePreviewLogin, and a same-origin assertion at each canvas/edit call site. Full affected suite passes, lint clean.

fully tested on both

https://plugprox--da-live--adobe.aem.live/canvas#/shsteimer/da-playground/index
https://plugprox--da-live--adobe.aem.live/edit#/shsteimer/da-playground/index

before
Screenshot 2026-09-28 at 11 25 47 AM

after:

Screenshot 2026-09-28 at 11 26 40 AM

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)

Checklist:

  • I have signed the Adobe Open Source CLA.
  • My code follows the code style of this project.
  • My change requires a change to the documentation.
  • I have updated the documentation accordingly.
  • I have read the CONTRIBUTING document.
  • I have added tests to cover my changes.
  • All new and existing tests passed.

Adds a shared getPreviewProxyDetails/toPreviewProxyUrl/ensurePreviewProxySession
helper in blocks/shared/preview-proxy.js and routes da-library, da-prepare,
canvas prepare-menu, ew-panel-extensions, and ew-tool-panel plugin/extension
URLs through it.

livePreviewLogin now takes a 4th getUrl param so the /gimme_cookie request
always targets the same origin the iframe/popup loads, fixing a mismatch where
canvas surfaces could authenticate against the prod preview origin while the
iframe loaded from stage-preview (or vice versa).

Adds unit coverage for preview-proxy.js (including ensurePreviewProxySession),
the getUrl branch of getLivePreviewUrl/livePreviewLogin, and a same-origin
assertion at each canvas/edit call site.

Assisted-by: GitHub Copilot
@aem-code-sync

aem-code-sync Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Hello, I'm the AEM Code Sync Bot and I will run some actions to deploy your branch.
In case there are problems, just click the checkbox below to rerun the respective action.

  • Re-sync branch
Commits

@shsteimer shsteimer changed the title fix(preview-proxy): align gimme_cookie origin with proxied plugin URLs fix(plugins): Use preview proxy for library and prepare menu plugins. Sep 24, 2026
Cross-org plugin URLs are left unchanged so public plugins hosted by
another org keep working and no gimme_cookie is requested for orgs the
user may not belong to.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Importing editor-utils.js from the prepare menu, tool panel and extension
panels pulled toolbar-controller into their module graphs, which changed
toolbar render timing and broke canvas tests in CI.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Window-experience plugins open in a new tab where sidekick handles
auth, so skip the preview proxy and gimme_cookie for them.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
ew-selection-toolbar.hide() calls close() on every nx-menu. The fixture
had no close(), so any toolbar render that landed during a canvas test
threw, which failed CI intermittently (including on main).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The CI failure was the nx-menu fixture, not the import graph, so the
separate preview-origin.js module isn't needed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@@ -1,4 +1,12 @@
class NxMenu extends HTMLElement {}
class NxMenu extends HTMLElement {
open = false;

@shsteimer shsteimer Sep 28, 2026 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this test fixture change isn't stricly related, but prevents intermittent failures on TypeError: m.close is not a function

Other CI runs that failed with the same  error:

• main: https://github.com/adobe/da-live/actions/runs/35979776106
• main: https://github.com/adobe/da-live/actions/runs/35972047005
•  imgswap  PR: https://github.com/adobe/da-live/actions/runs/35888552143

Comment thread blocks/shared/preview-proxy.js Outdated
import { getLivePreviewUrl } from './constants.js';
import { livePreviewLogin } from './utils.js';

const AEM_HOST = /\.(aem|hlx)\.(page|live)$/;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Think we should not have hlx here any more aem is fine.

shsteimer and others added 2 commits September 30, 2026 08:32
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

This branch was successfully deployed

1 active deployment
plugprox — d9db9735 Deployed Oct 2, 2026 by aem-code-sync[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants