fix(startup): allow case-insensitive renderer paths on Windows

Normalizes local renderer file URLs to filesystem paths before comparison so Windows path casing cannot block the packaged application during initial navigation. Adds a regression test covering case-insensitive packaged renderer URLs and records the v2.0.27 release notes.
This commit is contained in:
Sucukdeluxe
2026-08-12 21:31:08 +02:00
parent 12179af243
commit d58c3a262f
5 changed files with 33 additions and 4 deletions
+13
View File
@@ -157,6 +157,19 @@ describe("browser-security", () => {
expect(attacker.preventDefault).toHaveBeenCalledTimes(1);
});
it("allows the packaged renderer file despite Windows path casing differences", () => {
const harness = createWindow();
const rendererUrl = "file:///C:/Program%20Files/MDD/resources/app.asar/build/renderer/index.html";
applyMainWindowSecurity(harness.window, {
rendererUrl,
externalHosts: githubOnly
});
const renderer = harness.navigate("file:///c:/program%20files/mdd/resources/app.asar/build/renderer/index.html");
expect(renderer.preventDefault).not.toHaveBeenCalled();
});
it("denies popups while allowing exact allowlisted HTTPS popup URLs through the shell", () => {
const harness = createWindow();
applyMainWindowSecurity(harness.window, {