server.ts 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519
  1. import * as electron from 'electron/main';
  2. import { EventEmitter } from 'events';
  3. import objectsRegistry from '@electron/internal/browser/remote/objects-registry';
  4. import { ipcMainInternal } from '@electron/internal/browser/ipc-main-internal';
  5. import { isPromise, isSerializableObject, deserialize, serialize } from '@electron/internal/common/type-utils';
  6. import type { MetaTypeFromRenderer, ObjectMember, MetaType, ObjProtoDescriptor } from '@electron/internal/common/remote/types';
  7. import { IPC_MESSAGES } from '@electron/internal/common/remote/ipc-messages';
  8. const v8Util = process._linkedBinding('electron_common_v8_util');
  9. const eventBinding = process._linkedBinding('electron_browser_event');
  10. const features = process._linkedBinding('electron_common_features');
  11. if (!features.isRemoteModuleEnabled()) {
  12. throw new Error('remote module is disabled');
  13. }
  14. // The internal properties of Function.
  15. const FUNCTION_PROPERTIES = [
  16. 'length', 'name', 'arguments', 'caller', 'prototype'
  17. ];
  18. type RendererFunctionId = [string, number] // [contextId, funcId]
  19. type FinalizerInfo = { id: RendererFunctionId, webContents: electron.WebContents, frameId: [number, number] };
  20. type CallIntoRenderer = (...args: any[]) => void
  21. // The remote functions in renderer processes.
  22. const rendererFunctionCache = new Map<string, WeakRef<CallIntoRenderer>>();
  23. // eslint-disable-next-line no-undef
  24. const finalizationRegistry = new FinalizationRegistry((fi: FinalizerInfo) => {
  25. const mapKey = fi.id[0] + '~' + fi.id[1];
  26. const ref = rendererFunctionCache.get(mapKey);
  27. if (ref !== undefined && ref.deref() === undefined) {
  28. rendererFunctionCache.delete(mapKey);
  29. if (!fi.webContents.isDestroyed()) {
  30. try {
  31. fi.webContents._sendToFrameInternal(fi.frameId, IPC_MESSAGES.RENDERER_RELEASE_CALLBACK, fi.id[0], fi.id[1]);
  32. } catch (error) {
  33. console.warn(`_sendToFrameInternal() failed: ${error}`);
  34. }
  35. }
  36. }
  37. });
  38. function getCachedRendererFunction (id: RendererFunctionId): CallIntoRenderer | undefined {
  39. const mapKey = id[0] + '~' + id[1];
  40. const ref = rendererFunctionCache.get(mapKey);
  41. if (ref !== undefined) {
  42. const deref = ref.deref();
  43. if (deref !== undefined) return deref;
  44. }
  45. }
  46. function setCachedRendererFunction (id: RendererFunctionId, wc: electron.WebContents, frameId: [number, number], value: CallIntoRenderer) {
  47. // eslint-disable-next-line no-undef
  48. const wr = new WeakRef<CallIntoRenderer>(value);
  49. const mapKey = id[0] + '~' + id[1];
  50. rendererFunctionCache.set(mapKey, wr);
  51. finalizationRegistry.register(value, {
  52. id,
  53. webContents: wc,
  54. frameId
  55. } as FinalizerInfo);
  56. return value;
  57. }
  58. const locationInfo = new WeakMap<Object, string>();
  59. // Return the description of object's members:
  60. const getObjectMembers = function (object: any): ObjectMember[] {
  61. let names = Object.getOwnPropertyNames(object);
  62. // For Function, we should not override following properties even though they
  63. // are "own" properties.
  64. if (typeof object === 'function') {
  65. names = names.filter((name) => {
  66. return !FUNCTION_PROPERTIES.includes(name);
  67. });
  68. }
  69. // Map properties to descriptors.
  70. return names.map((name) => {
  71. const descriptor = Object.getOwnPropertyDescriptor(object, name)!;
  72. let type: ObjectMember['type'];
  73. let writable = false;
  74. if (descriptor.get === undefined && typeof object[name] === 'function') {
  75. type = 'method';
  76. } else {
  77. if (descriptor.set || descriptor.writable) writable = true;
  78. type = 'get';
  79. }
  80. return { name, enumerable: descriptor.enumerable, writable, type };
  81. });
  82. };
  83. // Return the description of object's prototype.
  84. const getObjectPrototype = function (object: any): ObjProtoDescriptor {
  85. const proto = Object.getPrototypeOf(object);
  86. if (proto === null || proto === Object.prototype) return null;
  87. return {
  88. members: getObjectMembers(proto),
  89. proto: getObjectPrototype(proto)
  90. };
  91. };
  92. // Convert a real value into meta data.
  93. const valueToMeta = function (sender: electron.WebContents, contextId: string, value: any, optimizeSimpleObject = false): MetaType {
  94. // Determine the type of value.
  95. let type: MetaType['type'];
  96. switch (typeof value) {
  97. case 'object':
  98. // Recognize certain types of objects.
  99. if (value instanceof Buffer) {
  100. type = 'buffer';
  101. } else if (value && value.constructor && value.constructor.name === 'NativeImage') {
  102. type = 'nativeimage';
  103. } else if (Array.isArray(value)) {
  104. type = 'array';
  105. } else if (value instanceof Error) {
  106. type = 'error';
  107. } else if (isSerializableObject(value)) {
  108. type = 'value';
  109. } else if (isPromise(value)) {
  110. type = 'promise';
  111. } else if (Object.prototype.hasOwnProperty.call(value, 'callee') && value.length != null) {
  112. // Treat the arguments object as array.
  113. type = 'array';
  114. } else if (optimizeSimpleObject && v8Util.getHiddenValue(value, 'simple')) {
  115. // Treat simple objects as value.
  116. type = 'value';
  117. } else {
  118. type = 'object';
  119. }
  120. break;
  121. case 'function':
  122. type = 'function';
  123. break;
  124. default:
  125. type = 'value';
  126. break;
  127. }
  128. // Fill the meta object according to value's type.
  129. if (type === 'array') {
  130. return {
  131. type,
  132. members: value.map((el: any) => valueToMeta(sender, contextId, el, optimizeSimpleObject))
  133. };
  134. } else if (type === 'nativeimage') {
  135. return { type, value: serialize(value) };
  136. } else if (type === 'object' || type === 'function') {
  137. return {
  138. type,
  139. name: value.constructor ? value.constructor.name : '',
  140. // Reference the original value if it's an object, because when it's
  141. // passed to renderer we would assume the renderer keeps a reference of
  142. // it.
  143. id: objectsRegistry.add(sender, contextId, value),
  144. members: getObjectMembers(value),
  145. proto: getObjectPrototype(value)
  146. };
  147. } else if (type === 'buffer') {
  148. return { type, value };
  149. } else if (type === 'promise') {
  150. // Add default handler to prevent unhandled rejections in main process
  151. // Instead they should appear in the renderer process
  152. value.then(function () {}, function () {});
  153. return {
  154. type,
  155. then: valueToMeta(sender, contextId, function (onFulfilled: Function, onRejected: Function) {
  156. value.then(onFulfilled, onRejected);
  157. })
  158. };
  159. } else if (type === 'error') {
  160. return {
  161. type,
  162. value,
  163. members: Object.keys(value).map(name => ({
  164. name,
  165. value: valueToMeta(sender, contextId, value[name])
  166. }))
  167. };
  168. } else {
  169. return {
  170. type: 'value',
  171. value
  172. };
  173. }
  174. };
  175. const throwRPCError = function (message: string) {
  176. const error = new Error(message) as Error & {code: string, errno: number};
  177. error.code = 'EBADRPC';
  178. error.errno = -72;
  179. throw error;
  180. };
  181. const removeRemoteListenersAndLogWarning = (sender: any, callIntoRenderer: (...args: any[]) => void) => {
  182. const location = locationInfo.get(callIntoRenderer);
  183. let message = 'Attempting to call a function in a renderer window that has been closed or released.' +
  184. `\nFunction provided here: ${location}`;
  185. if (sender instanceof EventEmitter) {
  186. const remoteEvents = sender.eventNames().filter((eventName) => {
  187. return sender.listeners(eventName).includes(callIntoRenderer);
  188. });
  189. if (remoteEvents.length > 0) {
  190. message += `\nRemote event names: ${remoteEvents.join(', ')}`;
  191. remoteEvents.forEach((eventName) => {
  192. sender.removeListener(eventName, callIntoRenderer);
  193. });
  194. }
  195. }
  196. console.warn(message);
  197. };
  198. const fakeConstructor = (constructor: Function, name: string) =>
  199. new Proxy(Object, {
  200. get (target, prop, receiver) {
  201. if (prop === 'name') {
  202. return name;
  203. } else {
  204. return Reflect.get(target, prop, receiver);
  205. }
  206. }
  207. });
  208. // Convert array of meta data from renderer into array of real values.
  209. const unwrapArgs = function (sender: electron.WebContents, frameId: [number, number], contextId: string, args: any[]) {
  210. const metaToValue = function (meta: MetaTypeFromRenderer): any {
  211. switch (meta.type) {
  212. case 'nativeimage':
  213. return deserialize(meta.value);
  214. case 'value':
  215. return meta.value;
  216. case 'remote-object':
  217. return objectsRegistry.get(meta.id);
  218. case 'array':
  219. return unwrapArgs(sender, frameId, contextId, meta.value);
  220. case 'buffer':
  221. return Buffer.from(meta.value.buffer, meta.value.byteOffset, meta.value.byteLength);
  222. case 'promise':
  223. return Promise.resolve({
  224. then: metaToValue(meta.then)
  225. });
  226. case 'object': {
  227. const ret: any = meta.name !== 'Object' ? Object.create({
  228. constructor: fakeConstructor(Object, meta.name)
  229. }) : {};
  230. for (const { name, value } of meta.members) {
  231. ret[name] = metaToValue(value);
  232. }
  233. return ret;
  234. }
  235. case 'function-with-return-value': {
  236. const returnValue = metaToValue(meta.value);
  237. return function () {
  238. return returnValue;
  239. };
  240. }
  241. case 'function': {
  242. // Merge contextId and meta.id, since meta.id can be the same in
  243. // different webContents.
  244. const objectId: [string, number] = [contextId, meta.id];
  245. // Cache the callbacks in renderer.
  246. const cachedFunction = getCachedRendererFunction(objectId);
  247. if (cachedFunction !== undefined) { return cachedFunction; }
  248. const callIntoRenderer = function (this: any, ...args: any[]) {
  249. let succeed = false;
  250. if (!sender.isDestroyed()) {
  251. try {
  252. succeed = sender._sendToFrameInternal(frameId, IPC_MESSAGES.RENDERER_CALLBACK, contextId, meta.id, valueToMeta(sender, contextId, args));
  253. } catch (error) {
  254. console.warn(`_sendToFrameInternal() failed: ${error}`);
  255. }
  256. }
  257. if (!succeed) {
  258. removeRemoteListenersAndLogWarning(this, callIntoRenderer);
  259. }
  260. };
  261. locationInfo.set(callIntoRenderer, meta.location);
  262. Object.defineProperty(callIntoRenderer, 'length', { value: meta.length });
  263. setCachedRendererFunction(objectId, sender, frameId, callIntoRenderer);
  264. return callIntoRenderer;
  265. }
  266. default:
  267. throw new TypeError(`Unknown type: ${(meta as any).type}`);
  268. }
  269. };
  270. return args.map(metaToValue);
  271. };
  272. const isRemoteModuleEnabledImpl = function (contents: electron.WebContents) {
  273. const webPreferences = contents.getLastWebPreferences() || {};
  274. return webPreferences.enableRemoteModule != null ? !!webPreferences.enableRemoteModule : false;
  275. };
  276. const isRemoteModuleEnabledCache = new WeakMap();
  277. export const isRemoteModuleEnabled = function (contents: electron.WebContents) {
  278. if (!isRemoteModuleEnabledCache.has(contents)) {
  279. isRemoteModuleEnabledCache.set(contents, isRemoteModuleEnabledImpl(contents));
  280. }
  281. return isRemoteModuleEnabledCache.get(contents);
  282. };
  283. const handleRemoteCommand = function (channel: string, handler: (event: ElectronInternal.IpcMainInternalEvent, contextId: string, ...args: any[]) => void) {
  284. ipcMainInternal.on(channel, (event, contextId: string, ...args: any[]) => {
  285. let returnValue;
  286. if (!isRemoteModuleEnabled(event.sender)) {
  287. event.returnValue = null;
  288. return;
  289. }
  290. try {
  291. returnValue = handler(event, contextId, ...args);
  292. } catch (error) {
  293. returnValue = {
  294. type: 'exception',
  295. value: valueToMeta(event.sender, contextId, error)
  296. };
  297. }
  298. if (returnValue !== undefined) {
  299. event.returnValue = returnValue;
  300. }
  301. });
  302. };
  303. const emitCustomEvent = function (contents: electron.WebContents, eventName: string, ...args: any[]) {
  304. const event = eventBinding.createWithSender(contents);
  305. electron.app.emit(eventName, event, contents, ...args);
  306. contents.emit(eventName, event, ...args);
  307. return event;
  308. };
  309. const logStack = function (contents: electron.WebContents, code: string, stack: string | undefined) {
  310. if (stack) {
  311. console.warn(`WebContents (${contents.id}): ${code}`, stack);
  312. }
  313. };
  314. handleRemoteCommand(IPC_MESSAGES.BROWSER_WRONG_CONTEXT_ERROR, function (event, contextId, passedContextId, id) {
  315. const objectId: [string, number] = [passedContextId, id];
  316. const cachedFunction = getCachedRendererFunction(objectId);
  317. if (cachedFunction === undefined) {
  318. // Do nothing if the error has already been reported before.
  319. return;
  320. }
  321. removeRemoteListenersAndLogWarning(event.sender, cachedFunction);
  322. });
  323. handleRemoteCommand(IPC_MESSAGES.BROWSER_REQUIRE, function (event, contextId, moduleName, stack) {
  324. logStack(event.sender, `remote.require('${moduleName}')`, stack);
  325. const customEvent = emitCustomEvent(event.sender, 'remote-require', moduleName);
  326. if (customEvent.returnValue === undefined) {
  327. if (customEvent.defaultPrevented) {
  328. throw new Error(`Blocked remote.require('${moduleName}')`);
  329. } else {
  330. customEvent.returnValue = process.mainModule.require(moduleName);
  331. }
  332. }
  333. return valueToMeta(event.sender, contextId, customEvent.returnValue);
  334. });
  335. handleRemoteCommand(IPC_MESSAGES.BROWSER_GET_BUILTIN, function (event, contextId, moduleName, stack) {
  336. logStack(event.sender, `remote.getBuiltin('${moduleName}')`, stack);
  337. const customEvent = emitCustomEvent(event.sender, 'remote-get-builtin', moduleName);
  338. if (customEvent.returnValue === undefined) {
  339. if (customEvent.defaultPrevented) {
  340. throw new Error(`Blocked remote.getBuiltin('${moduleName}')`);
  341. } else {
  342. customEvent.returnValue = (electron as any)[moduleName];
  343. }
  344. }
  345. return valueToMeta(event.sender, contextId, customEvent.returnValue);
  346. });
  347. handleRemoteCommand(IPC_MESSAGES.BROWSER_GET_GLOBAL, function (event, contextId, globalName, stack) {
  348. logStack(event.sender, `remote.getGlobal('${globalName}')`, stack);
  349. const customEvent = emitCustomEvent(event.sender, 'remote-get-global', globalName);
  350. if (customEvent.returnValue === undefined) {
  351. if (customEvent.defaultPrevented) {
  352. throw new Error(`Blocked remote.getGlobal('${globalName}')`);
  353. } else {
  354. customEvent.returnValue = (global as any)[globalName];
  355. }
  356. }
  357. return valueToMeta(event.sender, contextId, customEvent.returnValue);
  358. });
  359. handleRemoteCommand(IPC_MESSAGES.BROWSER_GET_CURRENT_WINDOW, function (event, contextId, stack) {
  360. logStack(event.sender, 'remote.getCurrentWindow()', stack);
  361. const customEvent = emitCustomEvent(event.sender, 'remote-get-current-window');
  362. if (customEvent.returnValue === undefined) {
  363. if (customEvent.defaultPrevented) {
  364. throw new Error('Blocked remote.getCurrentWindow()');
  365. } else {
  366. customEvent.returnValue = event.sender.getOwnerBrowserWindow();
  367. }
  368. }
  369. return valueToMeta(event.sender, contextId, customEvent.returnValue);
  370. });
  371. handleRemoteCommand(IPC_MESSAGES.BROWSER_GET_CURRENT_WEB_CONTENTS, function (event, contextId, stack) {
  372. logStack(event.sender, 'remote.getCurrentWebContents()', stack);
  373. const customEvent = emitCustomEvent(event.sender, 'remote-get-current-web-contents');
  374. if (customEvent.returnValue === undefined) {
  375. if (customEvent.defaultPrevented) {
  376. throw new Error('Blocked remote.getCurrentWebContents()');
  377. } else {
  378. customEvent.returnValue = event.sender;
  379. }
  380. }
  381. return valueToMeta(event.sender, contextId, customEvent.returnValue);
  382. });
  383. handleRemoteCommand(IPC_MESSAGES.BROWSER_CONSTRUCTOR, function (event, contextId, id, args) {
  384. args = unwrapArgs(event.sender, [event.processId, event.frameId], contextId, args);
  385. const constructor = objectsRegistry.get(id);
  386. if (constructor == null) {
  387. throwRPCError(`Cannot call constructor on missing remote object ${id}`);
  388. }
  389. return valueToMeta(event.sender, contextId, new constructor(...args));
  390. });
  391. handleRemoteCommand(IPC_MESSAGES.BROWSER_FUNCTION_CALL, function (event, contextId, id, args) {
  392. args = unwrapArgs(event.sender, [event.processId, event.frameId], contextId, args);
  393. const func = objectsRegistry.get(id);
  394. if (func == null) {
  395. throwRPCError(`Cannot call function on missing remote object ${id}`);
  396. }
  397. try {
  398. return valueToMeta(event.sender, contextId, func(...args), true);
  399. } catch (error) {
  400. const err = new Error(`Could not call remote function '${func.name || 'anonymous'}'. Check that the function signature is correct. Underlying error: ${error.message}\nUnderlying stack: ${error.stack}\n`);
  401. (err as any).cause = error;
  402. throw err;
  403. }
  404. });
  405. handleRemoteCommand(IPC_MESSAGES.BROWSER_MEMBER_CONSTRUCTOR, function (event, contextId, id, method, args) {
  406. args = unwrapArgs(event.sender, [event.processId, event.frameId], contextId, args);
  407. const object = objectsRegistry.get(id);
  408. if (object == null) {
  409. throwRPCError(`Cannot call constructor '${method}' on missing remote object ${id}`);
  410. }
  411. return valueToMeta(event.sender, contextId, new object[method](...args));
  412. });
  413. handleRemoteCommand(IPC_MESSAGES.BROWSER_MEMBER_CALL, function (event, contextId, id, method, args) {
  414. args = unwrapArgs(event.sender, [event.processId, event.frameId], contextId, args);
  415. const object = objectsRegistry.get(id);
  416. if (object == null) {
  417. throwRPCError(`Cannot call method '${method}' on missing remote object ${id}`);
  418. }
  419. try {
  420. return valueToMeta(event.sender, contextId, object[method](...args), true);
  421. } catch (error) {
  422. const err = new Error(`Could not call remote method '${method}'. Check that the method signature is correct. Underlying error: ${error.message}\nUnderlying stack: ${error.stack}\n`);
  423. (err as any).cause = error;
  424. throw err;
  425. }
  426. });
  427. handleRemoteCommand(IPC_MESSAGES.BROWSER_MEMBER_SET, function (event, contextId, id, name, args) {
  428. args = unwrapArgs(event.sender, [event.processId, event.frameId], contextId, args);
  429. const obj = objectsRegistry.get(id);
  430. if (obj == null) {
  431. throwRPCError(`Cannot set property '${name}' on missing remote object ${id}`);
  432. }
  433. obj[name] = args[0];
  434. return null;
  435. });
  436. handleRemoteCommand(IPC_MESSAGES.BROWSER_MEMBER_GET, function (event, contextId, id, name) {
  437. const obj = objectsRegistry.get(id);
  438. if (obj == null) {
  439. throwRPCError(`Cannot get property '${name}' on missing remote object ${id}`);
  440. }
  441. return valueToMeta(event.sender, contextId, obj[name]);
  442. });
  443. handleRemoteCommand(IPC_MESSAGES.BROWSER_DEREFERENCE, function (event, contextId, id) {
  444. objectsRegistry.remove(event.sender, contextId, id);
  445. });
  446. handleRemoteCommand(IPC_MESSAGES.BROWSER_CONTEXT_RELEASE, (event, contextId) => {
  447. objectsRegistry.clear(event.sender, contextId);
  448. });