Upstream 1.7.2 prefixes most hand-written URLs with basePath via apiFetch / withBasePath, but four subpath-relevant spots were missed: - host-bridge: the sandbox iframe src was a bare "/plugin-sandbox" -> 404 under NEXT_PUBLIC_BASE_PATH, breaking all plugins. Wrap in withBasePath. - host-api doHttpPost: the same-origin /api/* plugin proxy used raw fetch on url.pathname -> 404 under a subpath. Route it through apiFetch. - admin branding preview <img>: unprefixed src -> broken thumbnail. - (sandbox) layout: drop the Geist font + globals.css imports. The sandbox runs with an opaque origin, so those assets are CORS-blocked; the plugin bundle and all host API calls travel over the postMessage bridge, so no same-origin asset fetch happens there.
27 lines
1.0 KiB
TypeScript
27 lines
1.0 KiB
TypeScript
import type { Metadata } from 'next';
|
|
import type { ReactNode } from 'react';
|
|
|
|
// The plugin sandbox iframe runs with an opaque origin (the `sandbox`
|
|
// attribute in production excludes `allow-same-origin` for isolation). Any
|
|
// asset request from this layout - bundled fonts, globals.css, etc. - is then
|
|
// cross-origin from the "null" origin to the host origin and gets blocked
|
|
// (fonts in particular require CORS). So this layout is intentionally minimal:
|
|
// no font imports, no CSS imports. Plugins ship their own styles, and both the
|
|
// plugin bundle and all host API calls travel over the postMessage RPC bridge,
|
|
// so the sandbox never fetches same-origin assets itself.
|
|
|
|
export const metadata: Metadata = {
|
|
title: 'Plugin sandbox',
|
|
robots: { index: false, follow: false },
|
|
};
|
|
|
|
export default function PluginSandboxLayout({ children }: { children: ReactNode }) {
|
|
return (
|
|
<html lang="en">
|
|
<body style={{ margin: 0, padding: 0, background: 'transparent' }}>
|
|
{children}
|
|
</body>
|
|
</html>
|
|
);
|
|
}
|