Skip to content

feat(html): render local HTML files with sandboxed assets - #156

Merged
wfnuser merged 3 commits into
devfrom
feat/local-html-files
Sep 13, 2026
Merged

wfnuser merged 3 commits into
devfrom
feat/local-html-files

Conversation

@wfnuser

@wfnuser wfnuser commented Sep 13, 2026

Copy link
Copy Markdown
Owner

Summary

  • Recognize .html/.htm files in local Space trees and preserve their extensions in routes, without changing Markdown behavior.
  • Render original HTML in a read-only preview with a Source toggle. Users can copy HTML plus assets into a Space; no Markdown conversion or import wizard is required.
  • Package relative CSS, JavaScript, images, fonts and supported media in memory, reusing the existing iframe sandbox/CSP.

Security and scope

  • Local desktop only; Cloud native HTML document/resource reading is not implemented by this PR.
  • Resource reads are restricted to the HTML document directory and descendants, with an extension allowlist; hidden paths, traversal and symbolic links are rejected.
  • Limits: 8 MiB per file, 24 MiB aggregate resource bytes, 160 resource paths.
  • Sandbox permits scripts without same-origin privileges; CSP blocks network requests, forms and nested remote content.
  • No arbitrary filesystem access or write API is exposed to document scripts.
  • No CPU/memory execution quota: hostile or buggy JavaScript can still cause performance problems.
  • CSS @import, dynamic module/resource loading, and cross-document link navigation are not supported. HTML editing/comments/history controls are intentionally not exposed.

Validation

  • npm test — rerun successfully before opening this PR.
  • npm run lint and npm run build.
  • Chromium and WebKit browser suite: 12 passing tests.
  • Rust library suite: 114 passing tests; cargo fmt --check.
  • Debug macOS application bundle built and launched.
  • Real FLAIR Super Reading HTML + assets copied into a local demo Space: formulas, images, zoom dialog, anchor scrolling and training/inference tab interaction verified in the native client.

The real paper/demo assets are not included in this PR; committed fixtures are small synthetic regression cases.

@netlify

netlify Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for cowiki-test ready!

Name Link
🔨 Latest commit d56228f
🔍 Latest deploy log https://app.netlify.com/projects/cowiki-test/deploys/6aa6a523de472d0008221a90
😎 Deploy Preview https://deploy-preview-156--cowiki-test.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@wfnuser
wfnuser merged commit c7e26c3 into dev Sep 13, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant