Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Bug]: Download buttons in HTML previews do nothing

Open Beginner friendly
#14,362 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
84/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
playwright, typescript
Domain
frontend, security

Research direction

Start with the CSP in apps/server/src/http.ts and locate the BrowserDocumentFrame iframe sandbox configuration. Reproduce the data-URL download in Playwright Chromium, then verify the sandbox settings allow the download while retaining the existing restrictions. Done means the HTML preview's download button saves the file without exposing cookies, storage, or the API.

Written by the indexing model from the issue text.

Description

Before submitting
  • I searched existing issues and did not find a duplicate.
  • I included enough detail to reproduce or investigate the problem.
Area

apps/server

Steps to reproduce
  1. Have an agent write an HTML file with a download button into the workspace, for example <a href="data:text/plain,hi" download="hi.txt">Download</a>.
  2. Open it from a chat link or the file preview.
  3. Click the button.
Expected behavior

The file downloads.

Actual behavior

Nothing happens, and the page shows no error. HTML assets are served with Content-Security-Policy: sandbox allow-scripts allow-forms allow-popups allow-modals (apps/server/src/http.ts), and BrowserDocumentFrame uses the same list for its iframe sandbox. Chromium drops every download from a sandboxed document unless the sandbox includes allow-downloads.

Adding it keeps the opaque origin, so cookies, storage, and the API stay out of reach.

Impact

Minor bug or occasional failure

Version or commit

main @ 0fcd5f906

Environment

macOS, T3 Code (Nightly) desktop. Also reproduced in Playwright Chromium by serving a page with the same header.

Workaround

Open the file outside T3 Code.

Dominant language
TypeScript
Stars
24k
Forks
6.3k
Avg merge
10h 20m
Merged PRs (30d)
309

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from pingdotgg/t3code

All issues in pingdotgg/t3code

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.