mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 11:12:35 +02:00
Two root causes in the "Camera View Mode = Window" path when auth is on (#979): 1. PrintersPage opened the popup with `noopener`, which severed the opener link and prevented the browser from copying sessionStorage (auth token) into the new window. The popup booted unauthenticated, POST /printers/camera/stream-token returned 401, and the <img> src went out with no ?token=. The backend's RequireCameraStreamTokenIfAuthEnabled then rejected every frame with "Valid camera stream token required". 2. CameraPage computed its stream URL from the module-level stream-token cache in withStreamToken(). That cache is populated by a useEffect in useStreamTokenSync that runs after render, so even after the token resolved the first post-arrival render still produced a tokenless URL and nothing triggered another render. Fix: - Drop `noopener` from the camera popup features (same-origin, trusted). - Subscribe CameraPage to the `camera-stream-token` React Query so the page re-renders the moment the token arrives. - Gate currentUrl on `waitingForStreamToken` and append the token directly from the reactive query value instead of the effect-synced module cache. Embedded overlay mode was unaffected. Added CameraPage tests covering both the auth-enabled (token required, src empty until it arrives, then includes ?token=) and auth-disabled (src rendered immediately without token) paths.