Skip to content

Conversation

@ghengeveld
Copy link
Member

@ghengeveld ghengeveld commented Jun 20, 2025

Closes #31791

What I did

Adds a try/catch around the call to window.top.navigator.clipboard and falls back to window.navigator.clipboard if it fails, which usually happens when loading Storybook in an iframe such as on StackBlitz.

Checklist for Contributors

Testing

The changes in this PR are covered in the following automated tests:

  • stories
  • unit tests
  • integration tests
  • end-to-end tests

Manual testing

This section is mandatory for all contributions. If you believe no manual test is necessary, please state so explicitly. Thanks!

Documentation

  • Add or update documentation reflecting your changes
  • If you are deprecating/removing a feature, make sure to update
    MIGRATION.MD

Checklist for Maintainers

  • When this PR is ready for testing, make sure to add ci:normal, ci:merged or ci:daily GH label to it to run a specific set of sandboxes. The particular set of sandboxes can be found in code/lib/cli-storybook/src/sandbox-templates.ts

  • Make sure this PR contains one of the labels below:

    Available labels
    • bug: Internal changes that fixes incorrect behavior.
    • maintenance: User-facing maintenance tasks.
    • dependencies: Upgrading (sometimes downgrading) dependencies.
    • build: Internal-facing build tooling & test updates. Will not show up in release changelog.
    • cleanup: Minor cleanup style change. Will not show up in release changelog.
    • documentation: Documentation only changes. Will not show up in release changelog.
    • feature request: Introducing a new feature.
    • BREAKING CHANGE: Changes that break compatibility in some way with current major version.
    • other: Changes that don't fit in the above categories.

🦋 Canary release

This pull request has been released as version 0.0.0-pr-31834-sha-8d2d9c94. Try it out in a new sandbox by running npx [email protected] sandbox or in an existing project with npx [email protected] upgrade.

More information
Published version 0.0.0-pr-31834-sha-8d2d9c94
Triggered by @ghengeveld
Repository storybookjs/storybook
Branch handle-cross-origin-clipboard-access
Commit 8d2d9c94
Datetime Fri Jun 20 14:29:06 UTC 2025 (1750429746)
Workflow run 15781218913

To request a new release of this pull request, mention the @storybookjs/core team.

core team members can create a new canary release here or locally with gh workflow run --repo storybookjs/storybook canary-release-pr.yml --field pr=31834

Greptile Summary

Improves clipboard access handling in Storybook by implementing a graceful fallback mechanism when running in cross-origin iframes like StackBlitz.

  • Added try/catch around window.top.navigator.clipboard access in code/core/src/components/components/syntaxhighlighter/syntaxhighlighter.tsx
  • Implemented fallback to window.navigator.clipboard when top-level clipboard access fails
  • Addresses security issue [Bug]: loading storybook in an iframe throws an error #31791 where Storybook would fail in iframe contexts
  • Fixes clipboard functionality in embedded environments without breaking existing behavior

@ghengeveld ghengeveld added bug patch:yes Bugfix & documentation PR that need to be picked to main branch ci:normal labels Jun 20, 2025
Copy link
Contributor

@greptile-apps greptile-apps bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

1 file reviewed, no comments
Edit PR Review Bot Settings | Greptile

@nx-cloud
Copy link

nx-cloud bot commented Jun 20, 2025

View your CI Pipeline Execution ↗ for commit 8d2d9c9.

Command Status Duration Result
nx run-many -t build --parallel=3 ✅ Succeeded 1m 17s View ↗

☁️ Nx Cloud last updated this comment at 2025-06-20 14:34:00 UTC

@nx-cloud
Copy link

nx-cloud bot commented Jun 20, 2025

View your CI Pipeline Execution ↗ for commit 8d2d9c9.

Command Status Duration Result
nx run-many -t build -c production --parallel=3 ✅ Succeeded 4m 4s View ↗

☁️ Nx Cloud last updated this comment at 2025-06-20 14:32:34 UTC

@storybook-app-bot
Copy link

Package Benchmarks

Commit: 8d2d9c9, ran on 20 June 2025 at 14:38:37 UTC

The following packages have significant changes to their size or dependencies:

storybook

Before After Difference
Dependency count 49 49 0
Self size 31.85 MB 31.87 MB 🚨 +16 KB 🚨
Dependency size 17.41 MB 17.41 MB 0 B
Bundle Size Analyzer Link Link

sb

Before After Difference
Dependency count 50 50 0
Self size 1 KB 1 KB 0 B
Dependency size 49.26 MB 49.27 MB 🚨 +16 KB 🚨
Bundle Size Analyzer Link Link

@storybook/cli

Before After Difference
Dependency count 216 216 0
Self size 582 KB 582 KB 0 B
Dependency size 94.58 MB 94.59 MB 🚨 +16 KB 🚨
Bundle Size Analyzer Link Link

@storybook/codemod

Before After Difference
Dependency count 185 185 0
Self size 31 KB 31 KB 0 B
Dependency size 78.71 MB 78.72 MB 🚨 +16 KB 🚨
Bundle Size Analyzer Link Link

@valentinpalkovic valentinpalkovic merged commit c2c6aaa into next Jun 23, 2025
61 of 62 checks passed
@valentinpalkovic valentinpalkovic deleted the handle-cross-origin-clipboard-access branch June 23, 2025 13:11
ghengeveld pushed a commit that referenced this pull request Jun 24, 2025
…ard-access

Core: Gracefully handle disallowed cross-origin clipboard access
(cherry picked from commit c2c6aaa)
@github-actions github-actions bot added the patch:done Patch/release PRs already cherry-picked to main/release branch label Jun 24, 2025
@ndelangen ndelangen removed the patch:yes Bugfix & documentation PR that need to be picked to main branch label Oct 28, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug ci:normal patch:done Patch/release PRs already cherry-picked to main/release branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: loading storybook in an iframe throws an error

4 participants