player: runtime-src is honoured for srcdoc only - an src embed always fetches the runtime from jsDelivr
I maintainer di solito rispondono entro 1 giorno
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 65/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- typescript
Direzione di ricerca
Start with the player entry points H, F, Pt, and _injectRuntime in hyperframes-player.global.js, then reproduce the src path using host.html and comp-nested.html. Done means an src embed requests /local-runtime.js when runtime-src is valid and otherwise retains the jsDelivr fallback, matching srcdoc behavior.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
<hyperframes-player> accepts a runtime-src attribute, and validates it carefully (http/https,
same-origin or loopback). But it is only ever read on the srcdoc path:
function H(r, e) { return qe(It(e, ...), Pt(r)); } // srcdoc -> honours runtime-src (Pt)
function F(r, e) { return Lt(e, ...); } // src -> URL params only
The probe that injects the runtime into an src iframe uses the module constant instead, with no
access to the host element:
var k = "https://cdn.jsdelivr.net/npm/@hyperframes/[email protected]/dist/hyperframe.runtime.iife.js";
_injectRuntime() {
this._runtimeInjected = true;
const t = doc.createElement("script");
t.src = k; // <- always the CDN
(doc.head || doc.documentElement).appendChild(t);
}
So an src embed cannot be given a local runtime. On an offline or air-gapped machine, or behind
a script-src 'self' CSP, the injection silently fails (it is inside a bare try {} catch {}),
__hf never appears, and the element eventually emits
error: "Composition timeline not found after 8s".
Reproduction
comp-nested.html — a [data-composition-src] child makes the probe inject immediately:
<!doctype html><html><head><meta charset="utf-8"></head><body>
<div id="root" data-composition-id="main" data-width="1080" data-height="1920">
<div data-composition-src="child.html" data-start="0" data-duration="5"></div>
</div>
</body></html>
host.html, served over http from the same origin as a local copy of the runtime:
<script src="https://cdn.jsdelivr.net/npm/@hyperframes/[email protected]/dist/hyperframes-player.global.js"></script>
<hyperframes-player src="comp-nested.html" runtime-src="/local-runtime.js"
width="1080" height="1920"></hyperframes-player>
Actual
The network panel shows
GET https://cdn.jsdelivr.net/npm/@hyperframes/[email protected]/dist/hyperframe.runtime.iife.js 200
and no request for /local-runtime.js. runtime-src passes the element's own validation and is
still ignored.
Expected
src and srcdoc resolve the runtime the same way: runtime-src when it is set and valid, the
jsDelivr default otherwise. Concretely, pass the resolved URL into the probe (it is already
computed by Pt(host)) instead of closing over the module constant, so an embed can serve its own
pinned copy.
Two smaller things that would help either way:
- the injected
<script>has noonerror, so a blocked or 404 runtime is indistinguishable from
a slow one — the element just times out after 8 s with a message about the timeline; - documenting
runtime-srcas srcdoc-only would at least make the current behaviour discoverable.
Environment
@hyperframes/player0.8.41, Chromium 141, Linux
Why it matters
A local review tool that embeds staged projects has to reach a CDN for every composition it opens,
or pre-inject the runtime into the served HTML itself (which is what we now do) — even though the
exact matching runtime is already sitting in node_modules/hyperframes/dist/.
- Lingua principale
- TypeScript
- Stelle
- 54.1k
- Fork
- 4.9k
- Merge medio
- 7h 18m
- PR unite (30g)
- 784
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di heygen-com/hyperframes
-
Docs: clarify that "Enable auto-update" is only available in the Claude Code terminal (CLI) /plugin UIForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
heygen-com/hyperframes#5027 ·
I maintainer di solito rispondono entro 1 giorno
-
fix(producer): propagate useGpu to HDR layered streaming encoderForse già presa @Monster-GM l’ha presa 2 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 87/100
heygen-com/hyperframes#5002 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
heygen-com/hyperframes#4702 · 1 commento · 1 reazione ·
I maintainer di solito rispondono entro 1 giorno
-
Studio catalog prompt editor has no accessible nameForse già presa @lorenzozanee l’ha presa 12 giorni fa. Apertabug difficulty/easy triage/ready
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
heygen-com/hyperframes#4384 ·
I maintainer di solito rispondono entro 1 giorno
-
lint: validate composition variables declared on supported root elementsForse di nuovo libera Una pull request per questa issue è stata chiusa senza essere unita. Apertabug difficulty/easy triage/ready
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
heygen-com/hyperframes#4383 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di heygen-com/hyperframes
Issue simili
-
triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
github/docs#46222 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
agent-ready area: config area: skills type: chore upstream: brain-kit
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 95/100
-
enhancement priority:low ready-for-dev
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno
-
bug escritorio mapa
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
marcosferr/reporte-ciudadano#4 · 1 commento ·
-
area: material/sort gemini-triaged needs triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
angular/components#33933 ·
I maintainer di solito rispondono entro 1 giorno