[Bug]: Download buttons in HTML previews do nothing
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 84/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- playwright, typescript
Research direction
Start with the CSP in apps/server/src/http.ts and locate the BrowserDocumentFrame iframe sandbox configuration. Reproduce the data-URL download in Playwright Chromium, then verify the sandbox settings allow the download while retaining the existing restrictions. Done means the HTML preview's download button saves the file without exposing cookies, storage, or the API.
Written by the indexing model from the issue text.
Description
Before submitting
- I searched existing issues and did not find a duplicate.
- I included enough detail to reproduce or investigate the problem.
Area
apps/server
Steps to reproduce
- Have an agent write an HTML file with a download button into the workspace, for example
<a href="data:text/plain,hi" download="hi.txt">Download</a>. - Open it from a chat link or the file preview.
- Click the button.
Expected behavior
The file downloads.
Actual behavior
Nothing happens, and the page shows no error. HTML assets are served with Content-Security-Policy: sandbox allow-scripts allow-forms allow-popups allow-modals (apps/server/src/http.ts), and BrowserDocumentFrame uses the same list for its iframe sandbox. Chromium drops every download from a sandboxed document unless the sandbox includes allow-downloads.
Adding it keeps the opaque origin, so cookies, storage, and the API stay out of reach.
Impact
Minor bug or occasional failure
Version or commit
main @ 0fcd5f906
Environment
macOS, T3 Code (Nightly) desktop. Also reproduced in Playwright Chromium by serving a page with the same header.
Workaround
Open the file outside T3 Code.
- Dominant language
- TypeScript
- Stars
- 24k
- Forks
- 6.3k
- Avg merge
- 10h 20m
- Merged PRs (30d)
- 309
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from pingdotgg/t3code
-
bug via-triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
pingdotgg/t3code#14452 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day
All issues in pingdotgg/t3code
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 78/100
lichess-org/api#678 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
PostHog/posthog.com#20628 ·
Maintainers usually reply within 1 day
-
bug status:Needs Triage
Difficulty 1/5 Under an hour Newbie friendliness 92/100
jupyterlab/jupyterlab#19964 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
agentscope-ai/QwenPaw#8064 · 1 comment ·
Maintainers usually reply within 1 day
-
area: notebooks-jupyter bug theme: new notebook frontend
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
posit-dev/positron#16347 · 1 comment ·
Maintainers usually reply within 1 day