Skip to content

fix: resolve the WebSocket URL from the page origin in blob workers - #5754

Closed
resure wants to merge 1 commit into
webpack:mainfrom
resure:fix/blob-worker-socket-url
Closed

resure wants to merge 1 commit into
webpack:mainfrom
resure:fix/blob-worker-socket-url

Conversation

@resure

@resure resure commented Sep 30, 2026 •

Copy link
Copy Markdown

Summary

The client is injected into workers too. Some setups start a worker from a blob: URL, for example a small blob that sets the public path and calls importScripts so worker code can load from a CDN (@gravity-ui/app-builder does this). In such a worker self.location has a blob: protocol and an empty hostname and port, so createSocketURL doesn't replace 0.0.0.0 with the page host and doesn't switch to wss:. If the dev server runs plain HTTP behind a TLS proxy, the worker tries ws://0.0.0.0/..., and on an HTTPS page new WebSocket throws SecurityError while the worker loads. Setting webSocketURL.protocol: 'wss' only turns that into endless reconnects to wss://0.0.0.0. With no protocol in the query, the client builds a blob://... socket URL.

A blob worker's self.location.origin is still the origin of the page that created it (checked in Chromium). With this change, a blob: worker with a real origin takes its hostname, protocol and port from that origin. Pages, http(s) workers, an explicitly set hostname or protocol, data: workers and blobs with an opaque ('null') origin work as before.

The same fix is proposed for @rspack/dev-server, whose client has the same code: rstackjs/rspack-dev-server#267. There it was tested end to end: with the patch applied, a real app's blob worker on an HTTPS dev stand connects to the page host and receives HMR updates. In this repository only the unit tests cover it.

What kind of change does this PR introduce?

fix

Did you add tests for your changes?

Yes. createSocketURL.test.js gets four blob-worker cases: an HTTPS page, an HTTP page, a custom port and an explicit hostname. All four fail without the fix. They go at the end of the table on purpose: the client opens its socket on import using the location left by the previous case, so a blob case in the middle would break the import for the cases after it on unfixed code. No e2e worker test was added.

Does this PR introduce a breaking change?

No.

If relevant, what needs to be documented once your changes are merged or what have you added to the documentation?

Nothing. A patch changeset is included.

Notice: this pr is mostly AI-generated. It originated from similar PR (rstackjs/rspack-dev-server#267) to rspack-dev-server which I verified on a real app.

@changeset-bot

changeset-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 2b721a1

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
webpack-dev-server Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@linux-foundation-easycla

Copy link
Copy Markdown

CLA Not Signed

@resure
resure marked this pull request as ready for review September 30, 2026 20:41
@resure

resure commented Sep 30, 2026

Copy link
Copy Markdown
Author

Wow, this "easy"-cla, docu-sign bullshit is beyond me, sorry. Closing this PR, but feel free to grab patch if somebody would need it: https://gist.github.com/resure/bc376397ef0df3669e696d4ea8b76812

@resure resure closed this Sep 30, 2026
@resure
resure deleted the fix/blob-worker-socket-url branch September 30, 2026 20:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant