Repository navigation
fix(server): allow downloads from HTML previews - #14363
stickerdaniel wants to merge 1 commit into
Conversation
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This changes the default security policy and iframe sandbox for every HTML preview, enabling downloads and broadening an existing browser permission. Despite the small, focused diff, the always-on security-boundary change warrants human review. You can add or adjust custom eligibility rules. Learn more. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: pingdotgg/t3code/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe server Content-Security-Policy and browser HTML iframe sandbox now include ChangesHTML preview downloads
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Bug fix Suggested reviewers: Fixed issue severity: <fixed_issue_severity>Low</fixed_issue_severity> Merge Risk: ⚪ Minimal · up to The change enables the requested preview downloads, and no concrete merge-blocking risk is established by the supplied context. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to HTML previews can now initiate downloads while retaining their isolated origin. No additional app or native privileges were demonstrated, but desktop save confirmation and repeated or interrupted download behavior remain unverified. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Note This comment is posted by Julius' dot The download-button failure in #14362 is clear, and both sandbox changes address it. The unresolved direction is whether HTML previews should also be able to start downloads without a user click: the PR explicitly identifies that consequence, and neither the linked issue nor this discussion contains a maintainer decision on it. Can a maintainer confirm the intended download behavior and scope, including page-initiated downloads and the desktop save flow? The prior-approval rule calls for agreeing intentional behavior changes first. Leaving this open for that decision; the Chromium result and 23 passing header tests are useful evidence, while desktop behavior remains unverified. |
Closes #14362.
What Changed
HTML previews may start downloads.
allow-downloadsjoins the sandbox in the CSP served with HTML assets and in the file preview iframe. Both need it, because the iframe sandbox and the document's CSP sandbox combine.Why
A page's own download button did nothing, without any error. The opaque origin stays intact.
Trade-off: the token also lets a page start a download on load without a click. Chromium has no sandbox token limited to user-initiated downloads. Desktop shows Electron's save dialog; a browser client follows its download settings.
Verified with
vp test run apps/server/src/http.test.ts(23/23), fmt and lint. In Chromium, a page under the old policies downloaded nothing; under the new ones the file downloaded. Not run in the desktop or mobile apps.Checklist
Claude Opus 5.5 via Claude Code in T3 Code.