Skip to content

fix(ui): keep a relative URL as recorded in Mock this request - #289

Merged
erkamyaman merged 2 commits into
mainfrom
fix/h-http
Oct 11, 2026
Merged

erkamyaman merged 2 commits into
mainfrom
fix/h-http

Conversation

@erkamyaman

@erkamyaman erkamyaman commented Oct 11, 2026 •

Copy link
Copy Markdown
Member

What and why

Mock this request in the SSR & HTTP tab fills the rule form from a recorded call. It built the URL pattern with pathOf(), which resolves the URL against a dummy origin and returns pathname + search. That puts a / in front of a relative URL. A call to api/heroes?page=2 (relative URLs like this are common, for example in the Tour of Heroes tutorial) got the pattern /api/heroes?page=2.

Rule patterns without * match as a substring of req.urlWithParams, and api/heroes?page=2 doesn't contain /api/heroes?page=2. So the rule was saved and listed but never fired, on the client or during SSR, with nothing explaining why.

mockPattern now strips the origin only from absolute URLs (with a scheme, or starting with //). A relative URL stays as recorded, which still matches the absolute SSR URL as a substring. Redacted values still become *.

How it was verified

New test in app/src/__tests__/network-response-preview.test.ts. On main the pattern is /api/heroes?page=2. With the fix it's api/heroes?page=2. All panel and package tests pass.

  • pnpm commit:check (commit messages follow the guidelines)
  • pnpm format:check
  • pnpm typecheck (includes the ngc template checks)
  • pnpm test:panel and pnpm test:devtools (all passing)
  • pnpm skills:check (when .claude/ changed): not changed
  • Docs in apps/docs updated (one sentence in inspectors/ssr-http.md)
  • pnpm extension:build and extension/ui committed
  • Checked in the browser with axe (when the UI changed): logic change only, no markup or style change

Summary by CodeRabbit

  • Bug Fixes
    • Relative URLs are now preserved as entered when creating request mock patterns, while absolute URLs continue to use their path and query.
  • Documentation
    • Clarified how relative URLs are handled when mocking a request.

Mock this request built the rule's URL pattern by resolving the call's URL
against a dummy origin, which put a slash in front of a relative URL. A call
to api/heroes?page=2 got the pattern /api/heroes?page=2, and since patterns
without * match as a substring of the request URL, the rule never fired.
Only absolute URLs lose their origin now; a relative URL stays as the app
wrote it.
@github-actions github-actions Bot added area: panel The devtools panel app (app/) area: extension The Chrome extension area: docs The documentation site labels Oct 11, 2026
@coderabbitai

coderabbitai Bot commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: a9bf26e5-8079-4ff0-9c0e-494309a6f62e

📥 Commits

Reviewing files that changed from the base of the PR and between df35fd8 and 3a2d276.


⛔ Files ignored due to path filters (1)
  • extension/ui/assets/index-EXPZcZbM.js is excluded by !**/assets/index-[0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-].js

📒 Files selected for processing (4)
  • app/src/pages/network-inspector.ts
  • apps/docs/src/content/inspectors/ssr-http.md
  • extension/ui/assets/browser-agent-rpc-BXhoSh1z-CufAYnYw.js
  • extension/ui/index.html

 ______________________________________________________________________________________________________________________
< Separate views from models. Gain flexibility at low cost by designing your application in terms of models and views. >
 ----------------------------------------------------------------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 3824356b-2bcd-40e4-bd76-dc34b46a0f61


📥 Commits

Reviewing files that changed from the base of the PR and between 58273c6 and df35fd8.



⛔ Files ignored due to path filters (1)
  • extension/ui/assets/index-Bc_tTXxC.js is excluded by !**/assets/index-[0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-].js


📒 Files selected for processing (5)
  • app/src/__tests__/network-response-preview.test.ts
  • app/src/pages/network-inspector.ts
  • apps/docs/src/content/inspectors/ssr-http.md
  • extension/ui/assets/browser-agent-rpc-BXhoSh1z-Bpd00b-y.js
  • extension/ui/index.html


Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 0 remain after this review.




📝 Walkthrough
📝 Walkthrough

Walkthrough

The mock pattern now preserves relative recorded URLs and converts absolute and protocol-relative URLs to path and query. A test and documentation update cover relative URLs. The extension UI entry point and browser-agent RPC module reference an updated JavaScript asset.

Changes

Relative URL Mocking

Layer / File(s) Summary
Preserve relative request URLs
app/src/pages/network-inspector.ts, app/src/__tests__/network-response-preview.test.ts, apps/docs/src/content/inspectors/ssr-http.md
mockPattern keeps relative URLs unchanged, converts absolute and protocol-relative URLs to path and query, and retains redaction with *. The test checks a relative URL pattern, and the instructions clarify that relative URLs remain relative.

Extension UI Asset References

Layer / File(s) Summary
Update JavaScript asset references
extension/ui/index.html, extension/ui/assets/browser-agent-rpc-BXhoSh1z-Bpd00b-y.js
The module script and browser-agent RPC module now reference index-Bc_tTXxC.js instead of index-CgvJVwtz.js.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix



Merge Risk: ⚪ Minimal · up to df35f

Relative request URLs remain usable in generated mock rules, and the updated extension asset references resolve correctly. No merge-blocking behavior change is evident.

Security Architecture Review

Security architecture risk: 🔵 Low · up to df35f

The change retains existing permissions and development-only scope. However, a dot-relative URL can produce a rule that matches the browser request but misses its absolute SSR equivalent. An intended mocked request could therefore continue toward the real service. No new public access or credential compromise was established.

Retained concerns

  • Low · reliability · inferred: For a recorded ./api or ../api request, the generated pattern now retains the dot-relative spelling. If its SSR equivalent is an absolute URL, a saved both-side mock no longer matches it, although the base-generated /api pattern did. Normal request handling then continues and may reach the real service instead of supplying the intended mock. Exposure is limited to development interception and requires explicit rule submission.
Security review details

Security Blast Radius

  • inferred — Effective scope is matching requests passing through the development interceptor on the selected side and method; the draft defaults to both sides. Patterns remain intentionally unanchored, so they are not host or tenant isolation controls. Preserving a bare relative pattern can broaden textual matching without granting new network authority.

Security Findings and Attack Paths

  • inferred — The supported adverse path requires explicit submission of a dot-relative mock and an SSR request using its resolved absolute form. The rule can miss and permit normal handling, potentially reaching the real service. This establishes conditional containment loss, not an attacker exploit, credential disclosure, or privilege escalation.

Trust Boundaries and Controls

  • observed — Recorded input does not activate a rule by itself. Draft validation, explicit submission, server-side action authorization and sanitization remain between recorded data and interception. The changed helper does not remove those controls.

Resilience and Maintainability Implications

  • inferred — Pattern preservation does not introduce a new rule identity, state owner, cleanup path or update ordering. Server acceptance and broadcast remain authoritative. Uncertainty around concurrent full-list edits or a committed RPC with an interrupted response belongs to the unchanged lifecycle, not a newly demonstrated stranded-state condition.

Pre-merge checks | Passed 4 | Failed 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 20.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 3 files. (2 skipped: 2… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes the main change: preserving relative URLs as recorded in the Mock this request flow.
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.


Full details: Docstring Coverage

Explanation

Docstring coverage is 20.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 3 files. (2 skipped: 2 unsupported.)




  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR



🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Failed ❌

View logs ↗
3a2d276 2026-10-11T07:49:17.374Z View logs ↗
  • Build: Failed ❌

View logs ↗
df35fd8 2026-10-11T03:22:03.940Z View logs ↗

# Conflicts:
#	extension/ui/assets/browser-agent-rpc-BXhoSh1z-Bpd00b-y.js
#	extension/ui/assets/browser-agent-rpc-BXhoSh1z-CQUbrXfP.js
#	extension/ui/assets/browser-agent-rpc-BXhoSh1z-CU2PEOZW.js
#	extension/ui/assets/index-BbaJhK0y.js
#	extension/ui/assets/index-Bc_tTXxC.js
#	extension/ui/assets/index-CgvJVwtz.js
#	extension/ui/index.html
@erkamyaman
erkamyaman merged commit e8b64f2 into main Oct 11, 2026
6 of 8 checks passed
@erkamyaman
erkamyaman deleted the fix/h-http branch October 11, 2026 07:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: docs The documentation site area: extension The Chrome extension area: panel The devtools panel app (app/)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant