Skip to content

fix(player): honor runtime discovery and source in embeds - #5244

Open
user-github-me wants to merge 1 commit into
heygen-com:mainfrom
user-github-me:fix/player-src-runtime-discovery
Open

user-github-me wants to merge 1 commit into
heygen-com:mainfrom
user-github-me:fix/player-src-runtime-discovery

Conversation

@user-github-me

@user-github-me user-github-me commented Oct 8, 2026 •

Copy link
Copy Markdown

Fixes #4002
Fixes #4003

A src embed can mistake the shared window.__hf shader namespace for the runtime bridge. On current main it can report ready from document metadata while seeking leaves the authored timeline at zero; nested scenes can remain unmounted. Check the actual __player bridge so standalone timelines remain driveable and nested scenes receive the runtime.

Use the existing validated runtime-src resolver for probe injection as well as srcdoc. A blocked or missing runtime now emits a load error with its URL, stops probing, and marks that document failed. Detach the error handler when stopping or restarting so an old script cannot fail the next document. Same-origin/loopback validation and pinned-CDN fallback stay intact.

Follows the scope described in unmerged #4246, with before/after captures and additional failure/recovery coverage.

Before

Main at 188475aaf: CDN access blocked; every embed has runtime-src="/local-runtime.js" and receives seek(1). The shader namespace leaves its marker at x=40 instead of x=200. Nested scenes stay empty, and the plain nested embed fetches jsDelivr and times out.

Before: main leaves shader timelines undriven and nested scenes empty

After

Identical fixture HTML, same blocked-CDN policy. All four embeds load and seek to x=200; nested scenes use /local-runtime.js, expose __player, and register their child timelines. No CDN requests or browser runtime errors.

After: all four embeds seek correctly and nested scenes use the local bridge

Validation

  • Seven new probe cases fail on main; all 552 player tests pass after the fix (16 new cases including bridge priority, URL policy, late errors, failure latching, and recovery). Disabled script loading in Happy DOM is configured as successful; explicit error events test failures.
  • Real Chrome 152 with built player, local GSAP, and local core runtime: four before/after embeds above; separate real 404 runtime emits its URL error in 230 ms, then changing runtime-src recovers and seeks correctly.
  • All four fixture projects pass composition lint and strict browser checks.
  • Player build/runtime-version pin, both player typechecks, repository lint, and changed-file formatting pass.
  • Sandbox origin browser check passes. One-run load/scrub smoke check passes its thresholds (cold 604 ms; warm 84 ms; inline/isolated scrub p95 16.3/17.8 ms).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant