Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

player: runtime-src is honoured for srcdoc only - an src embed always fetches the runtime from jsDelivr

Đang mở
#4,003 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

@srikarsunchu đang làm issue này rồi.

Từ ngày 21/9/2026.

  • #4246 của @srikarsunchu — đang mở

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
65/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
typescript
Lĩnh vực
frontend, web-dev

Hướng nghiên cứu

Start with the player entry points H, F, Pt, and _injectRuntime in hyperframes-player.global.js, then reproduce the src path using host.html and comp-nested.html. Done means an src embed requests /local-runtime.js when runtime-src is valid and otherwise retains the jsDelivr fallback, matching srcdoc behavior.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

triage/needs-triage
Summary

<hyperframes-player> accepts a runtime-src attribute, and validates it carefully (http/https,
same-origin or loopback). But it is only ever read on the srcdoc path:

function H(r, e) { return qe(It(e, ...), Pt(r)); }   // srcdoc  -> honours runtime-src (Pt)
function F(r, e) { return Lt(e, ...); }              // src     -> URL params only

The probe that injects the runtime into an src iframe uses the module constant instead, with no
access to the host element:

var k = "https://cdn.jsdelivr.net/npm/@hyperframes/[email protected]/dist/hyperframe.runtime.iife.js";
_injectRuntime() {
  this._runtimeInjected = true;
  const t = doc.createElement("script");
  t.src = k;                       // <- always the CDN
  (doc.head || doc.documentElement).appendChild(t);
}

So an src embed cannot be given a local runtime. On an offline or air-gapped machine, or behind
a script-src 'self' CSP, the injection silently fails (it is inside a bare try {} catch {}),
__hf never appears, and the element eventually emits
error: "Composition timeline not found after 8s".

Reproduction

comp-nested.html — a [data-composition-src] child makes the probe inject immediately:

<!doctype html><html><head><meta charset="utf-8"></head><body>
  <div id="root" data-composition-id="main" data-width="1080" data-height="1920">
    <div data-composition-src="child.html" data-start="0" data-duration="5"></div>
  </div>
</body></html>

host.html, served over http from the same origin as a local copy of the runtime:

<script src="https://cdn.jsdelivr.net/npm/@hyperframes/[email protected]/dist/hyperframes-player.global.js"></script>
<hyperframes-player src="comp-nested.html" runtime-src="/local-runtime.js"
                    width="1080" height="1920"></hyperframes-player>
Actual

The network panel shows

GET https://cdn.jsdelivr.net/npm/@hyperframes/[email protected]/dist/hyperframe.runtime.iife.js  200

and no request for /local-runtime.js. runtime-src passes the element's own validation and is
still ignored.

Expected

src and srcdoc resolve the runtime the same way: runtime-src when it is set and valid, the
jsDelivr default otherwise. Concretely, pass the resolved URL into the probe (it is already
computed by Pt(host)) instead of closing over the module constant, so an embed can serve its own
pinned copy.

Two smaller things that would help either way:

  • the injected <script> has no onerror, so a blocked or 404 runtime is indistinguishable from
    a slow one — the element just times out after 8 s with a message about the timeline;
  • documenting runtime-src as srcdoc-only would at least make the current behaviour discoverable.
Environment
  • @hyperframes/player 0.8.41, Chromium 141, Linux
Why it matters

A local review tool that embeds staged projects has to reach a CDN for every composition it opens,
or pre-inject the runtime into the served HTML itself (which is what we now do) — even though the
exact matching runtime is already sitting in node_modules/hyperframes/dist/.

Ngôn ngữ chính
TypeScript
Star
54.1k
Fork
4.9k
Merge trung bình
7 giờ 19 phút
Pull request đã merge (30 ngày)
746

Chuẩn bị môi trường

Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của heygen-com/hyperframes

Tất cả issue của heygen-com/hyperframes

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.