Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# 1.0.6
- Fixed check for receiving events on different `baseUrl` - #55 and #57

# 1.0.4
- Now supporting `baseUrl` with different path than `/`

Expand Down
4 changes: 2 additions & 2 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "react-drawio",
"version": "1.0.5",
"version": "1.0.6",
"type": "module",
"description": "React component for integrating the Diagrams (draw.io) embed iframe",
"main": "index.js",
Expand Down
19 changes: 15 additions & 4 deletions src/utils/handleEvent.ts
Original file line number Diff line number Diff line change
@@ -1,11 +1,22 @@
import { EmbedEvents } from '../types';

type EventHandler = {
[key in EmbedEvents['event']]?: (data: Extract<EmbedEvents, { event: key }>) => void;
[key in EmbedEvents['event']]?: (
data: Extract<EmbedEvents, { event: key }>
) => void;
};

export function handleEvent(event: MessageEvent, handlers: EventHandler, baseUrl?: string) {
if (!event.origin.includes('embed.diagrams.net') && (baseUrl && !event.origin.includes(baseUrl))) {
export function handleEvent(
event: MessageEvent,
handlers: EventHandler,
baseUrl?: string
) {
if (
!event.origin.includes('embed.diagrams.net') &&
baseUrl &&
!baseUrl.includes(event.origin) &&
!event.origin.includes(baseUrl)
Comment on lines +15 to +18
Copy link
Preview

Copilot AI Jul 3, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rather than using string includes for URL matching, parse baseUrl with the URL API (e.g. new URL(baseUrl).origin) and compare origins directly for reliability.

Suggested change
!event.origin.includes('embed.diagrams.net') &&
baseUrl &&
!baseUrl.includes(event.origin) &&
!event.origin.includes(baseUrl)
new URL(event.origin).origin !== 'https://embed.diagrams.net' &&
baseUrl &&
new URL(baseUrl).origin !== new URL(event.origin).origin &&
new URL(event.origin).origin !== new URL(baseUrl).origin

Copilot uses AI. Check for mistakes.

) {
Comment on lines +9 to +19
Copy link
Preview

Copilot AI Jul 3, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nitpick] The compound conditional for origin checks is complex—consider extracting it into a descriptive helper function (e.g. isAllowedOrigin(event.origin, baseUrl)) to improve readability.

Suggested change
export function handleEvent(
event: MessageEvent,
handlers: EventHandler,
baseUrl?: string
) {
if (
!event.origin.includes('embed.diagrams.net') &&
baseUrl &&
!baseUrl.includes(event.origin) &&
!event.origin.includes(baseUrl)
) {
function isAllowedOrigin(origin: string, baseUrl?: string): boolean {
return (
origin.includes('embed.diagrams.net') ||
(baseUrl &&
(baseUrl.includes(origin) || origin.includes(baseUrl)))
);
}
export function handleEvent(
event: MessageEvent,
handlers: EventHandler,
baseUrl?: string
) {
if (!isAllowedOrigin(event.origin, baseUrl)) {

Copilot uses AI. Check for mistakes.

return;
}

Expand All @@ -23,4 +34,4 @@ export function handleEvent(event: MessageEvent, handlers: EventHandler, baseUrl
} catch {
//
}
};
}
6 changes: 6 additions & 0 deletions stories/DiagramsEmbed.stories.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -472,3 +472,9 @@ export const MergeMultiple: Story = {
}
]
};

export const BaseUrl: Story = {
args: {
baseUrl: 'https://jgraph.github.io/drawio/src/main/webapp/index.html'
}
};