Read a Markdown file as the document it is
A .md previewed as its own source, which is reading the punctuation rather than the notes. It now opens rendered, with Rendered | Source in the dialog footer for anyone who wants what the file actually says. Markdown only; a .txt has nothing to toggle between. Rendering is `marked`, sanitised by DOMPurify -- the one the app already carries for mail. Markdown is not a safe subset of anything: raw HTML passes through it by design, so a <script> in a file somebody uploaded or shared into the account is a script tag unless something takes it out. Images become links rather than pictures. An image in a Markdown file is either a relative path, which has no base to resolve against here, or a URL somewhere else, which fetches on open and tells that server the file was read -- the tracking pixel this app blocks in mail. The link keeps the alt text and the address, so nothing vanishes silently. Fixes the PDF preview while here, which never worked: securityHeaders put X-Frame-Options: DENY on every response including the blob route, so the iframe showed Chrome's "refused to connect" where the file should have been -- in Files today and in mail attachments long before that. The middleware now leaves a header the route has set, and a PDF served inline says SAMEORIGIN. Nothing else on the server is framable.
This commit is contained in:
@@ -88,3 +88,22 @@ test("a Sieve script larger than a compressing hop's threshold survives the prox
|
||||
origin.close();
|
||||
}
|
||||
});
|
||||
|
||||
test("only a PDF blob may be framed, and only by us", async () => {
|
||||
/*
|
||||
* The PDF preview is an iframe, and the blanket X-Frame-Options: DENY on
|
||||
* every response blocked it -- the dialog showed Chrome's "refused to
|
||||
* connect" where the file should have been. The middleware now leaves a
|
||||
* header a route has already set, so this pins both halves: the exception
|
||||
* exists, and it did not become the rule.
|
||||
*/
|
||||
const app = createApp();
|
||||
const health = await app.request("/api/health");
|
||||
assert.equal(health.headers.get("x-frame-options"), "DENY");
|
||||
|
||||
const { securityHeadersFor } = await import("./app.js");
|
||||
assert.equal(securityHeadersFor("application/pdf", true), "SAMEORIGIN");
|
||||
assert.equal(securityHeadersFor("application/pdf", false), "DENY");
|
||||
assert.equal(securityHeadersFor("image/png", true), "DENY");
|
||||
assert.equal(securityHeadersFor("text/html", true), "DENY");
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user