← Files HA Interaction AuditARCHIVED FILE
skills/ha-interaction-audit/assets/harness/network-policy.mjs
2.24 KB · Oct 2, 2026 · 00:33 UTC
export const VIRTUAL_ORIGIN = 'https://ha-audit.invalid';
export function createResourcePolicy(resources) {
const table = new Map();
for (const item of resources) {
const url = new URL(item.path, VIRTUAL_ORIGIN);
if (!item.path.startsWith('/') || item.path.startsWith('//') ||
url.origin !== VIRTUAL_ORIGIN || url.hash || url.username || url.password ||
table.has(url.href) || typeof item.body !== 'string') {
throw new Error('Invalid or duplicate fixture resource');
}
table.set(url.href, {body:item.body, contentType:item.contentType || 'text/plain'});
}
return (method, rawURL) => {
let url;
try { url = new URL(rawURL); } catch { return {action:'abort', reason:'invalid-url'}; }
const resource = table.get(url.href);
if (method !== 'GET' || !resource || url.origin !== VIRTUAL_ORIGIN)
return {action:'abort', reason:'unmapped-request'};
return {action:'fulfill', ...resource};
};
}
// This function must remain self-contained for evaluateOnNewDocument().
export function installBrowserGuards() {
const events = [];
const add = (surface, probe = false) => events.push({surface, probe, blocked:true, at:Date.now()});
let probing = false;
Object.defineProperty(window, '__HA_AUDIT_GUARDS', {value:{
events,
probe(fn) { probing = true; try { return fn(); } finally { probing = false; } }
}, configurable:false, writable:false});
for (const name of ['WebSocket','EventSource','Worker','SharedWorker','RTCPeerConnection','webkitRTCPeerConnection']) {
const blocked = class {
static CONNECTING = 0; static OPEN = 1; static CLOSING = 2; static CLOSED = 3;
constructor() { add(name, probing); throw new Error('Fixture blocks native '+name); }
};
Object.defineProperty(window, name, {value:blocked, writable:false, configurable:false});
}
Object.defineProperty(navigator, 'sendBeacon', {value:() => {add('beacon', probing);return false;}});
if (navigator.serviceWorker) {
Object.defineProperty(navigator.serviceWorker, 'register', {value:() => {
add('serviceWorker', probing); return Promise.reject(new Error('Fixture blocks service workers'));
}});
}
Object.defineProperty(window, 'open', {value:() => {add('window.open', probing);return null;}});
}
SHA-256: 8bcf2bc758ce0259a9113516aa77f6bcc26a8fbddc07e2641ecf2f7228db5251