fix: harden service worker cache policy
This commit is contained in:
@@ -87,6 +87,30 @@ const CACHE_FIRST_PATTERNS = [
|
|||||||
/src\/scripts\/pwa-.*\.js$/
|
/src\/scripts\/pwa-.*\.js$/
|
||||||
];
|
];
|
||||||
|
|
||||||
|
// Explicit allowlist for any response that may be written to Cache Storage.
|
||||||
|
// Unknown GET responses are deliberately excluded by default.
|
||||||
|
const CACHEABLE_PATHS = new Set([
|
||||||
|
'/',
|
||||||
|
'/index.html',
|
||||||
|
'/manifest.json',
|
||||||
|
'/src/styles/pwa.css',
|
||||||
|
'/logo/icon-192x192.png',
|
||||||
|
'/logo/icon-512x512.png',
|
||||||
|
'/logo/favicon.ico',
|
||||||
|
'/src/pwa/pwa-manager.js',
|
||||||
|
'/src/pwa/install-prompt.js',
|
||||||
|
'/src/scripts/pwa-register.js',
|
||||||
|
'/src/scripts/pwa-offline-test.js'
|
||||||
|
]);
|
||||||
|
|
||||||
|
function isSensitivePath(pathname) {
|
||||||
|
return SENSITIVE_PATTERNS.some(pattern => pattern.test(pathname));
|
||||||
|
}
|
||||||
|
|
||||||
|
function isCacheableStaticPath(pathname) {
|
||||||
|
return CACHEABLE_PATHS.has(pathname);
|
||||||
|
}
|
||||||
|
|
||||||
self.addEventListener('message', (event) => {
|
self.addEventListener('message', (event) => {
|
||||||
if (event.data && event.data.type === 'PWA_INSTALLED') {
|
if (event.data && event.data.type === 'PWA_INSTALLED') {
|
||||||
self.clients.matchAll().then(clients => {
|
self.clients.matchAll().then(clients => {
|
||||||
@@ -191,7 +215,7 @@ self.addEventListener('fetch', (event) => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Skip sensitive endpoints
|
// Skip sensitive endpoints
|
||||||
if (SENSITIVE_PATTERNS.some(pattern => pattern.test(url.pathname))) {
|
if (isSensitivePath(url.pathname)) {
|
||||||
console.log('🔒 Skipping cache for sensitive endpoint:', url.pathname);
|
console.log('🔒 Skipping cache for sensitive endpoint:', url.pathname);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -304,11 +328,16 @@ async function cacheFirst(request) {
|
|||||||
|
|
||||||
// Network First strategy with Response cloning fix
|
// Network First strategy with Response cloning fix
|
||||||
async function networkFirst(request) {
|
async function networkFirst(request) {
|
||||||
|
const url = new URL(request.url);
|
||||||
try {
|
try {
|
||||||
const networkResponse = await fetch(request);
|
const networkResponse = await fetch(request);
|
||||||
if (networkResponse && networkResponse.ok) {
|
if (networkResponse && networkResponse.ok) {
|
||||||
// Only cache non-sensitive successful responses
|
// Only cache explicitly known-safe static responses.
|
||||||
if (!SENSITIVE_PATTERNS.some(pattern => pattern.test(request.url))) {
|
if (
|
||||||
|
url.origin === self.location.origin &&
|
||||||
|
isCacheableStaticPath(url.pathname) &&
|
||||||
|
!isSensitivePath(url.pathname)
|
||||||
|
) {
|
||||||
// Clone the response before caching
|
// Clone the response before caching
|
||||||
const responseToCache = networkResponse.clone();
|
const responseToCache = networkResponse.clone();
|
||||||
const cache = await caches.open(DYNAMIC_CACHE);
|
const cache = await caches.open(DYNAMIC_CACHE);
|
||||||
@@ -336,12 +365,18 @@ async function networkFirst(request) {
|
|||||||
|
|
||||||
// Stale While Revalidate strategy with Response cloning fix
|
// Stale While Revalidate strategy with Response cloning fix
|
||||||
async function staleWhileRevalidate(request) {
|
async function staleWhileRevalidate(request) {
|
||||||
|
const url = new URL(request.url);
|
||||||
const cachedResponse = await caches.match(request);
|
const cachedResponse = await caches.match(request);
|
||||||
|
|
||||||
const networkResponsePromise = fetch(request)
|
const networkResponsePromise = fetch(request)
|
||||||
.then((networkResponse) => {
|
.then((networkResponse) => {
|
||||||
if (networkResponse && networkResponse.ok &&
|
if (
|
||||||
!SENSITIVE_PATTERNS.some(pattern => pattern.test(request.url))) {
|
networkResponse &&
|
||||||
|
networkResponse.ok &&
|
||||||
|
url.origin === self.location.origin &&
|
||||||
|
isCacheableStaticPath(url.pathname) &&
|
||||||
|
!isSensitivePath(url.pathname)
|
||||||
|
) {
|
||||||
// Clone the response before caching
|
// Clone the response before caching
|
||||||
const responseToCache = networkResponse.clone();
|
const responseToCache = networkResponse.clone();
|
||||||
caches.open(DYNAMIC_CACHE)
|
caches.open(DYNAMIC_CACHE)
|
||||||
|
|||||||
Reference in New Issue
Block a user