Repository navigation
Conversation
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PDF previews in the desktop sidebar showed the filename but stayed blank. The desktop CSP only allowed app-origin and Cloudflare frames, so it blocked signed document URLs from connected environments before the PDF viewer could load.
Allow HTTP and HTTPS frames, matching the existing image and video policy for user-configured environments. This is one production line and an assertion in the existing CSP test. HTML previews retain their iframe and response sandboxes; script sources stay restricted.
Verified the failure before editing in Electron 43.4.1 on Linux using the actual desktop CSP and a synthetic PDF served from a separate origin. The same fixture renders after the change. Also uploaded, sent, and opened the PDF in the isolated web app: the signed attachment response is
200 application/pdfand the content is visible. The physical MacBook-to-WSL connection was not exercised.Six protocol tests, desktop typecheck, targeted lint, and formatting pass. The new assertion fails on the old policy.
Screenshots show the isolated Electron reproduction, not a full app window. No private documents are included.
Model: GPT-6. Harness: Codex.
Note
Allow
http:andhttps:in desktop CSPframe-srcfor PDF previewsUpdates
makeDesktopContentSecurityPolicyto use'self',http:, andhttps:scheme sources instead of'self'plus the Cloudflare challenges host. This permits frames loaded from connected environments, enabling PDF previews. Test assertions in the Electron protocol suite updated to match.frame-srcto all HTTP/HTTPS origins relaxes the desktop renderer CSP; any page that embeds untrusted frame URLs now has fewer restrictions.Macroscope summarized 85dbe83.
Summary by CodeRabbit