Repository navigation
[Bug]: Preview browser cannot open native apps via custom-scheme deep links #16251
Copy link
Copy link
Closed
Closed
Copy link
Labels
bugSomething is broken or behaving incorrectly.Something is broken or behaving incorrectly.via-triageFiled through npx t3 triageFiled through npx t3 triage
Description
Activity
- changed the title
[-][Bug]: Preview browser silently drops custom-scheme deep links, so SSO-to-desktop-app handoffs hang forever (slack://, zoom://, teams:// …)[/-][+][Bug]: Preview browser cannot open native apps via custom-scheme deep links[/+]on Oct 5, 2026 Note
Grok responding on behalf of Julius.
Triage
Thanks for the clear repro, @tensorcopy!
What I found
location.href = "slack://…"inside a preview guest is an external-protocol navigation. Electron 44 asks the session for theopenExternalpermission before launching the OS handler. The preview partition's permission handler inapps/desktop/src/preview/BrowserSession.tsallows clipboard read/write, notifications, and geolocation, but notopenExternal, so the request is denied and Electron treats the navigation as handled. The page stays where it is, nothing is logged, anddid-fail-loaddoesn't surface it (that handler also ignoresERR_ABORTED).POPUP_PROTOCOLS/previewWindowOpenActiononly decide whetherwindow.opengets a popup. Aslack://target is classified as"navigate"and loaded back into the same guest, hitting the same denial.setWindowOpenHandlerandwill-navigateinDesktopWindow.tsrun on the app window, not the preview guest.parseSafeExternalUrlrejectsslack://there and also hides Copy Link in the guest context menu, so custom-scheme links can't be copied out either.- The address bar can't be used as a fallback:
normalizePreviewUrlaccepts onlyhttp:/https:, and the submit handler swallows that error. The hover-only "Open in system browser" button opens the current https page, though cookies stay in the preview partition. The preview ⋮ menu has no equivalent item (see closed PR feat(web): open the preview page in the system browser from the menu #10833). - Related but separate: fix(markdown): make known app deep links clickable #15722 (allowlist for chat markdown links), [Bug]: Integrated browser denies Local Network Access, so Okta FastPass (and other loopback SSO helpers) cannot authenticate #9724 and [Bug]: Integrated browser reaches Google unsupported-browser page after sign-in and 2FA #14815 (loopback SSO and external-browser handoff).
Likely fix area
- Granting
openExternalfor every scheme would let any preview page launch arbitrary OS handlers without a prompt, so that's worth weighing against convenience. - Options include surfacing the denial visibly in the preview, with a user-initiated "Open" that routes through
shell.openExternal(possibly scoped per scheme or per origin), and making "Open in system browser" and Copy Link available for custom-scheme links from the ⋮ and context menus.
A maintainer will decide on the fix direction.
- addedbugSomething is broken or behaving incorrectly.Something is broken or behaving incorrectly.via-triageFiled through npx t3 triageFiled through npx t3 triage
on Oct 5, 2026
Metadata
Metadata
Assignees
Labels
bugSomething is broken or behaving incorrectly.Something is broken or behaving incorrectly.via-triageFiled through npx t3 triageFiled through npx t3 triage
Before submitting
Area
apps/desktop
Steps to reproduce
a registered OS handler, e.g.
location.href = "slack://open".Expected behavior
The native app opens, the same as in a normal browser — or the handoff at
least visibly fails.
Actual behavior
Nothing happens. The deep link is dropped silently: no app launches, no
error, no log, and the preview stays on the current page. Any page that
waits for the native app (e.g. a "Launching… you will be redirected in a
few moments" interstitial) hangs forever.
Impact
Preview tabs cannot complete any flow that needs to open a desktop app.
Version or commit
0.0.46-nightly.20261005.2689
Environment
macOS 26.7.1
Logs or stack traces
None — the failure is silent.