Skip to content

Commit c09043d

Browse files
author
hellojason3
committed
fix(deploy): allow reviewed public RPC fallbacks
1 parent 516d9b5 commit c09043d

1 file changed

Lines changed: 12 additions & 4 deletions

File tree

‎deploy/cloudflare-pages/deploy-privacy-bridge-demo.sh‎

Lines changed: 12 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -308,12 +308,20 @@ else
308308
fi
309309

310310
if multichain_enabled; then
311-
while IFS= read -r private_rpc_url; do
312-
if grep -RFl -- "$private_rpc_url" "$FRONTEND_DIR/dist" >/dev/null; then
313-
echo "refusing frontend publish: a private L1 RPC URL was embedded in dist" >&2
311+
public_rpc_allowlist="$FRONTEND_DIR/src/services/chainConfig.ts"
312+
while IFS=$'\t' read -r network runtime_rpc_url; do
313+
# A runtime upstream can itself be one of the source-reviewed, credentialless
314+
# public fallbacks. Those URLs are intentionally bundled; every other
315+
# runtime upstream (Alchemy keys, internal relays, and unknown endpoints)
316+
# must remain server-side only.
317+
if grep -Fq -- "$runtime_rpc_url" "$public_rpc_allowlist"; then
318+
continue
319+
fi
320+
if grep -RFl -- "$runtime_rpc_url" "$FRONTEND_DIR/dist" >/dev/null; then
321+
echo "refusing frontend publish: ${network} runtime L1 RPC URL was embedded in dist" >&2
314322
exit 1
315323
fi
316-
done < <(multichain_runtime_json | jq -r '.chains[].rpc_url')
324+
done < <(multichain_runtime_json | jq -r '.chains[] | [.network, .rpc_url] | @tsv')
317325

318326
while IFS=$'\t' read -r network bridge_address public_rpc_domain; do
319327
if ! grep -RFiq -- "$bridge_address" "$FRONTEND_DIR/dist"; then

0 commit comments

Comments
 (0)