Skip to content

fix(web): open document file links in the correct viewer - #16071

Open
JDeffner wants to merge 4 commits into
pingdotgg:mainfrom
JDeffner:fix/html-file-preview
Open

JDeffner wants to merge 4 commits into
pingdotgg:mainfrom
JDeffner:fix/html-file-preview

Conversation

@JDeffner

@JDeffner JDeffner commented Oct 5, 2026 •

Copy link
Copy Markdown

Fixes #16099. Fixes #16096.

HTML documents can open as source after a user selects source once, because t3code.renderBrowserFile=false persists globally. Document links with literal #, ?, or Unicode filenames can fail before rendering: browser-document checks truncate decoded paths as URLs, and the shared Markdown parser rejects characters in bare relative paths.

Keep HTML source mode local to the current document so new documents open rendered. Explicit line targets still open source, and Markdown/table preferences remain unchanged. Use the shared filesystem-path classifier for HTML/PDF previews. Accept Unicode letters, numbers, and combining marks, plus decoded #, ?, and %, in the existing relative-path patterns. Preserve exact filename spelling and separate URL queries/fragments before decoding. The Unicode fix extends the same path-recognition change already in this PR and reaches web, desktop, and mobile callers.

Based on nightly v0.0.46-nightly.20261005.2676 (7812230572f2). Prior content-type and desktop CSP fixes are already in this base. Related history: #9143, #10935, #11935, #11191, and #9140.

Validation:

  • Four render-state regressions failed before the preference fix. Eleven Unicode regressions failed before the parser extension, including the web document resolver and mobile link presentation.
  • Latest focused run: 240 shared, web, and mobile file-link tests passed. Coverage includes the reported Chinese PDF path, encoded paths, decomposed accents, Indic marks, Arabic numbers, supplementary-plane letters, line targets, literal delimiters, and external URL/route exclusions.
  • Earlier focused checks: 62 HTTP/asset-access and 21 file-preview/render-state tests passed. Those implementations are unchanged by the Unicode extension.
  • Client-runtime typecheck and targeted lint/format/diff checks pass for the extension. Web typecheck passed for the earlier viewer changes. The unchanged breadcrumb effect has an existing lint dependency warning.
  • T3 preview browser with isolated dev state: an existing local report changed from source to rendered while the old global preference remained false. Source toggling and explicit line targets worked.
  • Filename checks: an encoded report%23final.html link rendered the document and sibling CSS. Both literal and encoded 線性代數/期中 報告.html links in rendered Markdown opened the HTML document; its load script reported success. The Unicode line link opened source with line 3 highlighted.

Filename classification, before and after:

HTML source before the filename fix

Rendered HTML after the filename fix

Unicode links, before (ordinary relative web anchors) and after (the linked HTML document renders):

Unicode paths before the parser fix

Unicode HTML document after the parser fix

Screenshots use synthetic files. Native mobile was not tested; its shared link-presentation tests pass. No transport, asset-permission, or sandbox contracts change. Intermittent blank frames on reopening documents were observed separately and are not claimed fixed. Windows File Explorer launch failures remain tracked in #11780; this PR does not change the launcher.

Models: GPT-6-Astra and GPT-6.1-Sol. Harness: Codex through T3 Code.

@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Oct 5, 2026
@github-actions github-actions Bot added size:S 10-29 changed lines (additions + deletions). and removed size:XS 0-9 changed lines (additions + deletions). labels Oct 5, 2026
@github-actions github-actions Bot added size:M 30-99 changed lines (additions + deletions). and removed size:S 10-29 changed lines (additions + deletions). labels Oct 5, 2026
@JDeffner JDeffner changed the title fix(web): preserve literal paths when opening HTML and PDF files fix(web): open HTML documents in rendered view by default Oct 5, 2026
@JDeffner
JDeffner marked this pull request as ready for review October 5, 2026 15:15
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: pingdotgg/t3code/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 6733ac2b-be26-4320-a157-48bd2030bad3
📥 Commits

Reviewing files that changed from the base of the PR and between 6d4f26e and 2fa1ef6.

📒 Files selected for processing (4)
  • apps/mobile/src/lib/markdownLinks.test.ts
  • apps/web/src/components/files/browserDocumentPaths.test.ts
  • packages/client-runtime/src/markdownLinks.test.ts
  • packages/client-runtime/src/markdownLinks.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

Markdown file-link parsing now recognizes Unicode paths and encoded delimiters. Browser and PDF preview checks use the full path. HTML render selection and reveal handling are tracked for the current document.

Changes

Document preview behavior

Layer / File(s) Summary
Markdown file-link path parsing
packages/client-runtime/src/markdownLinks.ts, packages/client-runtime/src/markdownLinks.test.ts, apps/mobile/src/lib/markdownLinks.test.ts
Relative file paths now accept Unicode letters, combining marks, and numbers. Tests cover encoded delimiters, query and fragment handling, position targets, and Unicode file links.
Full-path preview classification
apps/web/src/browser/openFileInPreview.ts, apps/web/src/markdown-links.ts, apps/web/src/components/files/BrowserDocumentFrame.tsx, apps/web/src/components/files/browserDocumentPaths.test.ts, apps/web/src/markdown-links.test.ts
Browser and PDF checks test the full path without stripping query or fragment characters. Tests cover encoded and literal delimiters and paths whose final suffix is not a document extension.
Per-document HTML render state
apps/web/src/components/files/useFilePreviewRenderState.ts, apps/web/src/components/files/useFilePreviewRenderState.test.tsx, apps/web/src/components/files/FilePreviewPanel.tsx, docs/user/composer.md
The hook tracks HTML render state and reveal handling for the current document. FilePreviewPanel uses the hook, and tests cover document changes, remounts, and line requests. The documentation states that another HTML file opens in rendered view.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: juliusmarminge

Merge Risk: ⚪ Minimal · up to 2fa1e

Ordinary relative Unicode document links appear to benefit from this change. No confirmed issue blocks merging.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 2fa1e

The change is limited to file-link interpretation and document previews. The inspected paths retain existing file-access mediation and HTML isolation. No introduced vulnerability was verified, but end-to-end enforcement and recovery coverage remains incomplete.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — The inspected preview authority includes workspace preview files and explicit host-file previews on the selected environment. Workspace document claims can authorize permitted descendant assets relative to the document directory; host-media claims identify an exact canonical file. These scopes predate the PR and should not be described as single-file workspace isolation.

Security Findings and Attack Paths

  • inferred — Attacker-authored Markdown can make additional relative filenames actionable when the user opens a link. The widened patterns do not establish a new filesystem authority: equivalent explicitly relative or absolute file paths were already accepted. The mobile media fallback also already joined relative media paths to workspace context and issued media-file resources, so its lack of local containment is not newly introduced by these patterns.

Trust Boundaries and Controls

  • observed — The parser is a recognition mechanism, not the file-access enforcement boundary. Inspected server code validates workspace-relative paths, resolves canonical files, checks signed-token expiration, and restricts asset requests by claim scope. Host-media requests additionally check canonical path and file identity. These checks do not establish a broader tenant-authorization guarantee.

Resilience and Maintainability Implications

  • observed — Preview URL queries retain environment and resource identity, while a changed absolute path remounts the browser preview. The changed render-state hook does not modify asset issuance or retry logic. Lower-level retry and interruption behavior remains incompletely inspected.
🚥 Pre-merge checks | ✅ 1 | ❌ 2 | ❓ 2

❌ Failed checks (2 warnings, 2 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 14.29% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 11 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check ⚠️ Warning The description gives clear problem and change details, links issues, and reports focused tests and browser checks. However, it does not provide maintainer approval for the preference-scope decision, … Add the maintainer’s explicit approval comment for the preference-scope decision, or explain why this focused fix qualifies for the template’s approval exemption.
Linked Issues check ❓ Inconclusive For #16099, useFilePreviewRenderState keeps HTML render state local to the current path and defaults each new path or remount to rendered mode. Its tests cover the saved `t3code.renderBrowserFile=fa… Provide #16096's current state and coding requirements so its implementation and tests can be assessed.
Out of Scope Changes check ❓ Inconclusive The #16099 changes are in scope. The PR also changes browser-document path classification and shared Markdown link parsing for literal delimiters and Unicode filenames. The current PR description asso… Provide #16096's current state and scope to determine whether the path-classification and Markdown-parser changes are in scope.
✅ Passed checks (1 passed)
Check name Status Explanation
Title check ✅ Passed The title describes the file-link viewer changes, but it does not name the primary change: keeping HTML source mode local to the current document. It is still related to the changeset.
Full details: Linked Issues check

Explanation

For #16099, useFilePreviewRenderState keeps HTML render state local to the current path and defaults each new path or remount to rendered mode. Its tests cover the saved t3code.renderBrowserFile=false value, document changes, and line requests. FilePreviewPanel still opens an unhandled line request in source mode and preserves the Markdown and table preferences. The PR also says it fixes #16096, but that issue's requirements and state were not provided, so compliance with all claimed linked issues cannot be established.

Full details: Out of Scope Changes check

Explanation

The #16099 changes are in scope. The PR also changes browser-document path classification and shared Markdown link parsing for literal delimiters and Unicode filenames. The current PR description associates these changes with #16096, but #16096's issue details were not provided. The evidence does not establish whether those changes meet that issue's scope or are unrelated.

Full details: Description check

Explanation

The description gives clear problem and change details, links issues, and reports focused tests and browser checks. However, it does not provide maintainer approval for the preference-scope decision, which the linked issue identifies as needing review.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@JDeffner JDeffner changed the title fix(web): open HTML documents in rendered view by default fix(web): open document file links in the correct viewer Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M 30-99 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Selecting HTML source makes every later HTML document open as source [Bug]: Relative file links with non-ASCII paths don't open

1 participant