Skip to content

fix(desktop): allow PDF previews from connected environments - #10541

Closed
Gigioxx wants to merge 1 commit into
pingdotgg:mainfrom
Gigioxx:t3code/fix-pdf-preview-rendering
Closed

Gigioxx wants to merge 1 commit into
pingdotgg:mainfrom
Gigioxx:t3code/fix-pdf-preview-rendering

Conversation

@Gigioxx

@Gigioxx Gigioxx commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

PDF previews in the desktop sidebar showed the filename but stayed blank. The desktop CSP only allowed app-origin and Cloudflare frames, so it blocked signed document URLs from connected environments before the PDF viewer could load.

Allow HTTP and HTTPS frames, matching the existing image and video policy for user-configured environments. This is one production line and an assertion in the existing CSP test. HTML previews retain their iframe and response sandboxes; script sources stay restricted.

Verified the failure before editing in Electron 43.4.1 on Linux using the actual desktop CSP and a synthetic PDF served from a separate origin. The same fixture renders after the change. Also uploaded, sent, and opened the PDF in the isolated web app: the signed attachment response is 200 application/pdf and the content is visible. The physical MacBook-to-WSL connection was not exercised.

Six protocol tests, desktop typecheck, targeted lint, and formatting pass. The new assertion fails on the old policy.

Before After
Blank PDF frame Rendered PDF content

Screenshots show the isolated Electron reproduction, not a full app window. No private documents are included.

Model: GPT-6. Harness: Codex.

Note

Allow http: and https: in desktop CSP frame-src for PDF previews

Updates makeDesktopContentSecurityPolicy to use 'self', http:, and https: scheme sources instead of 'self' plus the Cloudflare challenges host. This permits frames loaded from connected environments, enabling PDF previews. Test assertions in the Electron protocol suite updated to match.

  • Risk: broadening frame-src to all HTTP/HTTPS origins relaxes the desktop renderer CSP; any page that embeds untrusted frame URLs now has fewer restrictions.

Macroscope summarized 85dbe83.

Summary by CodeRabbit

  • Bug Fixes
    • Improved desktop app compatibility with embedded content by allowing frames served over HTTP and HTTPS.
    • Frames loaded from the desktop application itself remain supported under the existing security policy.

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:XS 0-9 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants