diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-09 15:48:53 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-09 15:48:53 +0200 |
| commit | 56776934c2ddfbad4884b252da6f5fb25864b8db (patch) | |
| tree | b34aa2a9b71a3129c937d9d0cecaa39505afbd6b /packages/meshbay-hub/src/meshbay_hub/static/chat-app.js | |
| parent | 78b309d18efdd227c0efa42464988eaaf1483c16 (diff) | |
| download | meshbay-56776934c2ddfbad4884b252da6f5fb25864b8db.tar.gz | |
fix: the PDF preview needs object-src and frame-src, in both policies
A PDF preview showed the "this browser will not display the PDF inline"
fallback everywhere — in the desktop client since its first launch, and in
the browser since the hub started sending a CSP on 2026-09-01. It read as a
missing native feature because before that commit the hub sent no policy at
all, so Chrome had once worked and the application never had.
Two directives govern one feature. `files-app.js` decrypts the file in the
page and hands it to `<object type="application/pdf">` from a Blob; Chromium
loads that as plugin data (`object-src`, absent and therefore falling back to
`default-src 'none'`) and then renders it in an internal frame (`frame-src`).
Opening either alone changes nothing visible — the second refusal produces the
same fallback. `'self'` covers neither: a same-origin `blob:` URL is not
matched by it in either directive, measured in Chrome 152 against the deployed
page and in Electron 44 against the client's own policy.
`plugins` stays at its default `false`: the built-in viewer is not behind that
flag on Electron 44, verified by rendering one.
Widening `object-src` from `'none'` to `blob:` admits only what page script
minted itself, at a type this code sets — PDFium parsing bytes that came from
a node, which is what any browser does with the same file once downloaded.
Tests: each policy is pinned to carry `blob:` in both directives (each fails
if either token is removed), and the two policies are now held identical
directive by directive apart from the two deliberate differences — the comment
claiming they were the same had already drifted and nothing checked it. The
CSP source parser in test_desktop_shell.py read `//` comment lines as
directives, which is the "parse directives, not text" mistake this file
already records; it skips them now.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XauykfBvRrpy6RYbF6F7Wu
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/chat-app.js')
0 files changed, 0 insertions, 0 deletions