Pull requests / #719

#719 Add sandboxed HTML previews and scrollable chat code blocks

closed · @arytek · 0 Kommentare · Auf GitHub

SecurityDocumentationWindows

Beschreibung

HTML answers currently appear only as code, and long code blocks take up most of the chat. This adds a Preview button to HTML code blocks and caps code at a scrollable height of 500 pixels.

The preview opens in a centered dialog with 5% margins on each side. It renders inline HTML, CSS and JavaScript, with Reload, Close and Escape controls. Copy still returns the original code. Closing removes the iframe and restores focus, including when Escape is pressed inside the preview.

Generated code runs only after Preview is clicked. The iframe uses an opaque sandbox origin, and a content security policy blocks external subresources and fetches. It cannot read the chat DOM, browser storage or saved API key. HTML aliases and unlabelled full HTML documents are supported, including saved chat answers.

## Validation

- Browser regression checks passed on Edge at 1920 x 1080 and 390 x 844: rendering, interactive JavaScript, dimensions, internal code scrolling, reload, copy, multiple blocks, keyboard/focus, saved chats and sandbox isolation.
- 16 existing web-serving, host and origin validation tests passed.
- JavaScript syntax checks and git diff whitespace checks passed.
- Manually tested in the local Strata chat interface.
- The broader existing HTTP security suite encountered Windows connection-reset errors (WinError 10053) on Python 3.14. No backend code is changed.

The browser checks are included in tools/test_web_html_preview.js, with Playwright CLI commands documented at the top. Documentation is updated in docs/DETAILS.md.

Mehr auf der Site

Links zu Install, Modellen, Releases.