Skip to content

[AI-9623] Implement SDK host-side soft-mint embed origin for Angie Applications - #112

Draft
naftalis-elementor wants to merge 1 commit into
masterfrom
cursor/ai-9623-sdk-embed-origin-a38f
Draft

naftalis-elementor wants to merge 1 commit into
masterfrom
cursor/ai-9623-sdk-embed-origin-a38f

Conversation

@naftalis-elementor

Copy link
Copy Markdown
Contributor

Overview

This PR implements the host-side SDK functionality for soft-mint embed origin authentication for Angie Applications (NG-* apps), as specified in the HLD (section 6.1).

Relates to Jira ticket: https://elementor.atlassian.net/browse/AI-9623

Implementation Details

Core Functionality

  • Embed Token Minting: New embed-token.ts module handles minting, caching, and reminting of embed session tokens
  • API Integration: Calls POST /angie/embed/session with { appId } - browser sets Origin header automatically
  • Token Caching: Caches tokens per appId with 60-second skew window before expiry
  • Concurrent Request Coalescing: Multiple concurrent mint requests for the same appId share a single promise

PostMessage Contract

Host → Iframe (Set Token):

  • Type: angie/embed-token/set (MessageEventType.ANGIE_EMBED_TOKEN_SET)
  • Payload: { embedToken: string, exp: number }

Iframe → Host (Request Token):

  • Type: angie/embed-token/request (MessageEventType.ANGIE_EMBED_TOKEN_REQUEST)
  • Payload: none

Integration Points

  1. openSaaSPage.ts: Mints token before opening iframe when appId is provided; sends token via postMessage after iframe signals ANGIE_READY
  2. host-api-bridge.ts: Listens for ANGIE_EMBED_TOKEN_REQUEST messages from iframe and remints + resends token

Mint URL

POST ${iframeOrigin}/angie/embed/session
Body: { "appId": "NG-..." }
Response: { "embedToken": string, "exp": number }

Error Handling

  • Mint failures are logged but do not block iframe loading
  • Missing appId is handled gracefully (no token minted)
  • Network errors are caught and logged
  • Remint failures log errors but do not crash

Remint Behavior

  • Token is cached per appId until it expires (with 60s skew)
  • Iframe can request a fresh token via ANGIE_EMBED_TOKEN_REQUEST message
  • Host remints and sends new token via ANGIE_EMBED_TOKEN_SET
  • Concurrent remint requests are coalesced to avoid duplicate API calls

Testing

  • embed-token.test.ts: 14 tests covering mint, cache, remint, expiry, coalescing, error handling
  • openSaaSPage.test.ts: Updated with 5 new tests for token minting and postMessage integration
  • host-api-bridge.test.ts: Added 5 tests for remint request handling

All tests pass. Linter checks pass.

Notes

  • Keep existing ?origin= query behavior for UX/analytics (not used for auth)
  • No Turnstile/captcha in v1 (as per HLD)
  • No changes to Studio/angie-agents in this PR (SDK only)
  • API feature flag may be off in staging - implementation is soft-failing (logs + continues)

Related PRs (different repos)

  • API mint endpoint: elementor/elementor-ai#4454
  • EmbedTokenGuard: elementor/elementor-ai#4456
  • Iframe ensure + header: elementor/elementor-ai#4457
Open in Web Open in Cursor 

…plications

- Add embed token minting module (embed-token.ts) with caching and reminting logic
- Mint embed session token before opening iframe when appId is provided
- Send minted token to iframe via postMessage on ANGIE_READY event
- Handle embed token refresh requests from iframe (ANGIE_EMBED_TOKEN_REQUEST)
- Add new MessageEventType enums: ANGIE_EMBED_TOKEN_SET and ANGIE_EMBED_TOKEN_REQUEST
- Integrate with elementor-ai API endpoint: POST /angie/embed/session
- Implement token validation with 60s skew window before expiry
- Coalesce concurrent mint requests for same appId
- Add comprehensive unit tests for mint, cache, remint, and postMessage flows
- Use logger instead of console for error/warning messages
- Gracefully handle mint failures (log and continue without token)

Co-authored-by: naftalis <naftalis-elementor@users.noreply.github.com>
github-actions Bot added a commit that referenced this pull request Sep 23, 2026
github-actions Bot added a commit that referenced this pull request Sep 23, 2026
@github-actions

Copy link
Copy Markdown

🎬 Video Proof Test Results

Branch: cursor/ai-9623-sdk-embed-origin-a38f
Test Status: ✅ Passed

Clicked Ask Angie to open the loadSidebarV2 sidebar on the product editor POC.

📸 Screenshots

01
01

02
02

03
03

Artifacts are also available on the workflow run.

github-actions Bot added a commit that referenced this pull request Sep 23, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants