Skip to content

Secure HTML artifact previews with isolated execution#100

Merged
yaacovcorcos merged 3 commits into
mainfrom
feature/html-artifact-preview
Jul 23, 2026
Merged

Secure HTML artifact previews with isolated execution#100
yaacovcorcos merged 3 commits into
mainfrom
feature/html-artifact-preview

Conversation

@yaacovcorcos

@yaacovcorcos yaacovcorcos commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Summary

  • classify local HTML as static documents, browser-ready bundles, dev-server entrypoints, or unsupported before opening it
  • serve referenced local assets from a dedicated capability-scoped loopback listener with no Scient application routes
  • isolate executable artifacts from the normal browser and OAuth session
  • make dev-server startup generation-safe, readiness-based, and strictly process-owned
  • add native Windows and Linux localhost smoke coverage
  • document a reusable cross-platform clean-machine and manual-verification protocol

Security model

  • static previews are enabled by default with scripts disabled
  • executable bundle and dev-server flows fail closed unless SCIENT_EXECUTABLE_HTML_PREVIEW is explicitly enabled
  • grants are high-entropy, short-lived, revocable, bounded, workspace-confined, and limited to the inspected dependency graph
  • every request, including the root entry, revalidates canonical path containment and the allowlisted dependency graph
  • authoritative dev-server readiness and stop operations require exact PID, parent PID, or ancestor lineage; a matching working directory is presentation context only
  • the preview listener accepts only GET and HEAD for allowlisted MIME types and exposes no application RPC, WebSocket, or OAuth routes
  • artifact tabs use unique non-persistent Electron partitions; permissions, downloads, popups, frames, workers, WebSockets, external navigation, and cross-origin requests are denied
  • macOS and Linux grants use unique preview.localhost subdomains; Windows uses a unique ephemeral 127.0.0.1 port per grant

Final exact-head verification

  • reviewed head: 6587065
  • base: 1d2ef85
  • range-diff: all three commits patch-identical after the final rebase
  • local full test graph before the rebase: 12 of 12 tasks green, including 2,170 server tests with 7 intentional skips
  • local exact-head focused security and dev-runner tests: 49 passed
  • local exact-head format, typecheck, and lint green with 0 errors; git diff check clean
  • hosted run 30053740482: full CI, Windows Process Regression, Release Smoke, HTML Preview Platform Smoke on Linux, and HTML Preview Platform Smoke on Windows all green
  • documented normal desktop launch verified SCIENT_EXECUTABLE_HTML_PREVIEW=1 in both the exact-head Electron process and server process
  • no unresolved GitHub review threads

Visual certification boundary

A macOS visual run on the patch-identical feature implementation proved static render and thumbnail behavior, isolated interactive execution and reset, static external-browser handoff, and Markdown opening in rendered Preview. The final rebase changed no patch, and the only later code change tightened process ownership and root-file canonicalization without changing the UI. The exact-head desktop startup and rollout propagation were re-proven, but the Mac locked before the final identical click-through could be repeated. Native Linux and Windows exact-head smoke coverage is green. Executable previews remain explicitly opt-in.

Cross-platform smoke command

bun run --cwd apps/server test:html-preview-platform

@github-actions github-actions Bot added size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Jul 23, 2026
@yaacovcorcos
yaacovcorcos force-pushed the feature/html-artifact-preview branch 5 times, most recently from 265b44e to 8f96149 Compare July 23, 2026 21:20
@yaacovcorcos
yaacovcorcos force-pushed the feature/html-artifact-preview branch 2 times, most recently from e2ecbf4 to a82fb0d Compare July 23, 2026 21:51
@yaacovcorcos
yaacovcorcos force-pushed the feature/html-artifact-preview branch from a82fb0d to 6587065 Compare July 23, 2026 23:36
@yaacovcorcos
yaacovcorcos merged commit db689d6 into main Jul 23, 2026
10 checks passed
@yaacovcorcos
yaacovcorcos deleted the feature/html-artifact-preview branch July 23, 2026 23:52
yaacovcorcos added a commit that referenced this pull request Jul 24, 2026
* Route telemetry through ScientFactory gateway (#43)

* Fix unsigned macOS release signatures (#44)

* Add consent-aware desktop analytics (#47)

* Fix Claude terminal auth and connection recovery (#52)

* fix provider status refresh invariants

* fix Claude auth recovery

* Use direct OAuth for Grok sign-in (#53)

* Use direct OAuth for Grok sign-in

* Expose safe Grok OAuth browser fallback

* Secure Scient state initialization (#48)

* Secure Scient state initialization

* Allow legacy migration state test

* fix(security): harden private state files

* test(security): lock private file boundaries

* fix(security): reject unsafe private file nodes

* Supervise the desktop backend lifecycle (#49)

* Supervise the desktop backend lifecycle

* fix(desktop): preserve backend lifecycle ownership

* fix(desktop): replace semantically unready backends

* fix(desktop): close backend lifecycle races

* Supervise desktop connection recovery (#50)

* Supervise desktop connection recovery

* Isolate provider dialog browser fixtures

* fix(desktop): bind activation readiness generation

* fix(web): enforce single-owner connection recovery

* style(web): format connection recovery

* fix(web): satisfy connection transport types

* fix(web): harden stream and terminal recovery

* fix(web): fail closed on stuck stream cancellation

* fix(web): preserve terminal recovery ordering

* fix(web): clamp reconnect jitter ceilings

* fix(desktop): preserve connection wake after restack

* Define safe RPC recovery policies (#51)

* Define safe RPC recovery policies

* test(web): cover RPC recovery integration

* fix(web): recover after uncertain mutation failures

* test(web): type RPC recovery harness precisely

* fix(web): recover a failed replay generation

* Surface connection recovery diagnostics (#55)

* Surface connection recovery diagnostics

* test(web): cover connection recovery experience

* style(web): format recovery browser coverage

* fix(web): keep recovery diagnostics current

* Recover Codex sessions after authentication loss (#56)

* fix: recover Codex sessions after auth loss

* fix(codex): gate auth recovery by provider mode

* fix: harden Codex authentication recovery

* Support Linux desktop development launch (#57)

* Secure Scient state initialization

* Allow legacy migration state test

* Supervise the desktop backend lifecycle

* Supervise desktop connection recovery

* Define safe RPC recovery policies

* Surface connection recovery diagnostics

* Support Linux desktop development launch

* Isolate provider dialog browser fixtures

* fix(desktop): fail closed on unsafe Linux sandbox

* style(desktop): format Linux launcher hardening

* fix(release): preserve AppImage sandbox

* revert(release): keep AppImage migration out of launcher hardening

* fix(desktop): honor Linux user namespace sandbox

* Fix Antigravity browser authentication (#59)

* Fix Antigravity browser authentication

* Harden Antigravity authentication lifecycle

* Close Antigravity code window deterministically

* Keep Antigravity code submission cancellable

* Scope desktop signing credentials by platform (#60)

* Fix managed Antigravity updates, authentication, and dialog UX (#62)

* Fix trusted Antigravity install and update routing

* Fix Antigravity browser authentication and models

* Refine provider connection dialog actions

* Harden managed provider update recovery

* Stabilize macOS release identity (#63)

* Reduce unintended macOS permission prompts (#64)

* Stabilize macOS release identity

* Reduce unintended macOS permission prompts

* Apply repository formatting

* Control macOS notarization lifecycle (#65)

* Add Evidence to Note as a latent built-in (#70)

* Harden bidirectional chat rendering (#71)

* feat(web): harden bidirectional chat rendering

* fix(web): close bidi review gaps

* Add Medical Exam Study built-in (#72)

* Fix YAML frontmatter in Markdown previews (#69)

* Add T3-inspired project source dialog (#76)

* Add project source dialog

* Harden project source cloning

* Add T3-style right dock surfaces (#77)

* Add T3-style right dock surfaces

* Fix right dock test formatting

* fix: remove AppSnap startup announcement (#80)

* Add artifact preview cards to chat (#81)

* fix: select providers after connection (#82)

* Add message-level conversation forks (#78)

* Add message-level conversation forks

* Stabilize hosted fork browser test

* Close message fork boundary gaps

* Close final fork review gaps

* Resolve final fork recertification blockers

* Avoid replaying completed fork bootstrap

* Harden fork lineage and restart recovery

* Stabilize cold browser geometry startup

* Repair legacy fork title families

* Preserve unrecorded fork rename boundaries

* Clear drifted fork title lineage

* Improve desktop contribution workflow (#75)

* Set default base font to 15px and fix numeric editing (#79)

* Increase default base font size to 15px

* Fix manual font size editing

* Preserve external font setting updates

* Use recommended provider model defaults (#83)

* Use recommended provider model defaults

* Apply repository formatting

* Update browser expectation for Codex default

* Preserve explicit drafts before model discovery

* Respect live provider model availability

* Align desktop approval policy (#85)

* Fix release-candidate regressions (#86)

* Fix release candidate regressions

* Fix long transcript fork validation

* fix(release): preserve Linux sandbox (#87)

* fix(release): preserve Linux sandbox

* test(release): resolve nested builder package

* test(release): follow Bun package symlinks

* fix: preserve whitespace in folder browsing (#90)

* Collapse long assistant artifact shelves (#91)

* Remove project setup confirmation card (#93)

* Build unified notification system (#96)

* Hide provider setup banner on empty chats (#94)

* Hide provider setup banner on empty chats

* Stabilize empty provider banner coverage

* Harden provider banner browser readiness

* Fix Droid model discovery lifecycle (#95)

* Add ChatGPT-first voice transcription with local Whisper fallback (#97)

* feat(voice): define transcription backend contract

* feat(voice): add verified local transcription core

* Fix ChatGPT voice account context

* feat(voice): add ChatGPT-first local Whisper fallback

* Default Git writing to GPT-5.6 Luna (#99)

* Apply updated settings defaults once (#101)

* Apply updated settings defaults once

* Enable Studio in its browser fixture

* Improve voice dictation and active-turn composer controls (#102)

* Improve voice recording controls

* Add live local voice previews

* Keep voice send locked through completion

* Keep active-turn composer actions available

* Pin Whisper runtime source revision

* Fix voice transition regressions

* Fix folder picker navigation and project opening (#98)

* Fix folder picker navigation and project opening

* Tighten project setup choices

* Prevent duplicate folder picker submissions

* Fix Whisper runtime packaging on Windows (#104)

* fix: make Whisper packaging cross-platform safe

* fix: verify signed Windows Whisper runtime

* Secure HTML artifact previews with isolated execution (#100)

* feat: add secure HTML artifact previews

* fix: enforce HTML preview ownership boundaries

* Document cross-platform manual verification
yaacovcorcos added a commit that referenced this pull request Jul 24, 2026
* Route telemetry through ScientFactory gateway (#43)

* Fix unsigned macOS release signatures (#44)

* Add consent-aware desktop analytics (#47)

* Fix Claude terminal auth and connection recovery (#52)

* fix provider status refresh invariants

* fix Claude auth recovery

* Use direct OAuth for Grok sign-in (#53)

* Use direct OAuth for Grok sign-in

* Expose safe Grok OAuth browser fallback

* Secure Scient state initialization (#48)

* Secure Scient state initialization

* Allow legacy migration state test

* fix(security): harden private state files

* test(security): lock private file boundaries

* fix(security): reject unsafe private file nodes

* Supervise the desktop backend lifecycle (#49)

* Supervise the desktop backend lifecycle

* fix(desktop): preserve backend lifecycle ownership

* fix(desktop): replace semantically unready backends

* fix(desktop): close backend lifecycle races

* Supervise desktop connection recovery (#50)

* Supervise desktop connection recovery

* Isolate provider dialog browser fixtures

* fix(desktop): bind activation readiness generation

* fix(web): enforce single-owner connection recovery

* style(web): format connection recovery

* fix(web): satisfy connection transport types

* fix(web): harden stream and terminal recovery

* fix(web): fail closed on stuck stream cancellation

* fix(web): preserve terminal recovery ordering

* fix(web): clamp reconnect jitter ceilings

* fix(desktop): preserve connection wake after restack

* Define safe RPC recovery policies (#51)

* Define safe RPC recovery policies

* test(web): cover RPC recovery integration

* fix(web): recover after uncertain mutation failures

* test(web): type RPC recovery harness precisely

* fix(web): recover a failed replay generation

* Surface connection recovery diagnostics (#55)

* Surface connection recovery diagnostics

* test(web): cover connection recovery experience

* style(web): format recovery browser coverage

* fix(web): keep recovery diagnostics current

* Recover Codex sessions after authentication loss (#56)

* fix: recover Codex sessions after auth loss

* fix(codex): gate auth recovery by provider mode

* fix: harden Codex authentication recovery

* Support Linux desktop development launch (#57)

* Secure Scient state initialization

* Allow legacy migration state test

* Supervise the desktop backend lifecycle

* Supervise desktop connection recovery

* Define safe RPC recovery policies

* Surface connection recovery diagnostics

* Support Linux desktop development launch

* Isolate provider dialog browser fixtures

* fix(desktop): fail closed on unsafe Linux sandbox

* style(desktop): format Linux launcher hardening

* fix(release): preserve AppImage sandbox

* revert(release): keep AppImage migration out of launcher hardening

* fix(desktop): honor Linux user namespace sandbox

* Fix Antigravity browser authentication (#59)

* Fix Antigravity browser authentication

* Harden Antigravity authentication lifecycle

* Close Antigravity code window deterministically

* Keep Antigravity code submission cancellable

* Scope desktop signing credentials by platform (#60)

* Fix managed Antigravity updates, authentication, and dialog UX (#62)

* Fix trusted Antigravity install and update routing

* Fix Antigravity browser authentication and models

* Refine provider connection dialog actions

* Harden managed provider update recovery

* Stabilize macOS release identity (#63)

* Reduce unintended macOS permission prompts (#64)

* Stabilize macOS release identity

* Reduce unintended macOS permission prompts

* Apply repository formatting

* Control macOS notarization lifecycle (#65)

* Add Evidence to Note as a latent built-in (#70)

* Harden bidirectional chat rendering (#71)

* feat(web): harden bidirectional chat rendering

* fix(web): close bidi review gaps

* Add Medical Exam Study built-in (#72)

* Fix YAML frontmatter in Markdown previews (#69)

* Add T3-inspired project source dialog (#76)

* Add project source dialog

* Harden project source cloning

* Add T3-style right dock surfaces (#77)

* Add T3-style right dock surfaces

* Fix right dock test formatting

* fix: remove AppSnap startup announcement (#80)

* Add artifact preview cards to chat (#81)

* fix: select providers after connection (#82)

* Add message-level conversation forks (#78)

* Add message-level conversation forks

* Stabilize hosted fork browser test

* Close message fork boundary gaps

* Close final fork review gaps

* Resolve final fork recertification blockers

* Avoid replaying completed fork bootstrap

* Harden fork lineage and restart recovery

* Stabilize cold browser geometry startup

* Repair legacy fork title families

* Preserve unrecorded fork rename boundaries

* Clear drifted fork title lineage

* Improve desktop contribution workflow (#75)

* Set default base font to 15px and fix numeric editing (#79)

* Increase default base font size to 15px

* Fix manual font size editing

* Preserve external font setting updates

* Use recommended provider model defaults (#83)

* Use recommended provider model defaults

* Apply repository formatting

* Update browser expectation for Codex default

* Preserve explicit drafts before model discovery

* Respect live provider model availability

* Align desktop approval policy (#85)

* Fix release-candidate regressions (#86)

* Fix release candidate regressions

* Fix long transcript fork validation

* fix(release): preserve Linux sandbox (#87)

* fix(release): preserve Linux sandbox

* test(release): resolve nested builder package

* test(release): follow Bun package symlinks

* fix: preserve whitespace in folder browsing (#90)

* Collapse long assistant artifact shelves (#91)

* Remove project setup confirmation card (#93)

* Build unified notification system (#96)

* Hide provider setup banner on empty chats (#94)

* Hide provider setup banner on empty chats

* Stabilize empty provider banner coverage

* Harden provider banner browser readiness

* Fix Droid model discovery lifecycle (#95)

* Add ChatGPT-first voice transcription with local Whisper fallback (#97)

* feat(voice): define transcription backend contract

* feat(voice): add verified local transcription core

* Fix ChatGPT voice account context

* feat(voice): add ChatGPT-first local Whisper fallback

* Default Git writing to GPT-5.6 Luna (#99)

* Apply updated settings defaults once (#101)

* Apply updated settings defaults once

* Enable Studio in its browser fixture

* Improve voice dictation and active-turn composer controls (#102)

* Improve voice recording controls

* Add live local voice previews

* Keep voice send locked through completion

* Keep active-turn composer actions available

* Pin Whisper runtime source revision

* Fix voice transition regressions

* Fix folder picker navigation and project opening (#98)

* Fix folder picker navigation and project opening

* Tighten project setup choices

* Prevent duplicate folder picker submissions

* Fix Whisper runtime packaging on Windows (#104)

* fix: make Whisper packaging cross-platform safe

* fix: verify signed Windows Whisper runtime

* Secure HTML artifact previews with isolated execution (#100)

* feat: add secure HTML artifact previews

* fix: enforce HTML preview ownership boundaries

* Document cross-platform manual verification

* Use trash icon for voice cancel action (#106)

* Fix browser pane close and runtime recovery (#113)

* Isolate temporary Claude discovery from MCP servers (#116)

* Respect reduced motion in thread spinner (#84)

Adapt the upstream accessibility concept while retaining Scient-owned spinner geometry.

* Harden upstream-derived release tooling (#109)

* Salvage safe PR 61 interaction improvements (#107)

* Salvage safe PR 61 interaction improvements

* Harden terminal selection copy handling

* Adapt Studio Git gating and folder access (#108)

* Adapt Studio folder controls from Synara

* Gate Studio review command on repository detection

* Improve changed-file accessibility and density (#110)

* Add compact previews for bulky changed-file cards (#117)

* Improve changed-file accessibility and density

* Add compact changed-file previews

* Ensure changed-file previews show every file

* feat: add curated in-app release notes (#112)

* feat: add curated release notes workflow

* fix: harden release note experience

* refactor: share release note footer layout

* test: keep release note diagnostics concise

* Reject developer-facing release note copy

* Revert "Reject developer-facing release note copy"

This reverts commit 1006003.

* Harden release note structural validation

* Harden release note asset validation

* Resolve release note certification findings

* Bound release note PNG chunk parsing

* Validate all release note PNG chunk CRCs

* Fix browser multi-tab controls and menu occlusion (#119)

* Fix browser multi-tab controls and menu occlusion

* Keep browser sessions alive under overlays

* Harden browser overlay lifecycle coverage

* Complete browser tab and overlay semantics

* Restore focus after final browser tab closes

* Synchronize split-pane browser focus

* Harden Electron overlay lifecycle runner

* Isolate macOS Electron test bundle state

* Keep Electron lifecycle tests fully hermetic

* Resolve Electron sandbox from workspace package

* Guarantee Electron test harness cleanup

* Register Electron fixture cleanup immediately

* Restore focus after browser close controls

* Complete browser close focus recovery

* Handle early Electron test interruptions

* Cover earliest Electron setup interruption

* Refine branch and automation workflow affordances (#111)

* Refine upstream-derived workflow affordances

* Respect resolved automation triage state

* Fix native branch clipboard acceptance

* Document native workflow UX acceptance

* Add universal local file viewer (#114)

* Add universal local file viewer

* Harden local HTML preview capabilities

* Resolve HTML preview review blockers

* Close final HTML preview review gaps

* Fail closed on truncated active HTML

* Preserve complex HTML preview dependencies

* Fail closed on SVG runtime link mutation

* Block alternate network egress in HTML previews

* Recover HTML preview network setup

* Serialize HTML preview retries

* Occlude native HTML previews under overlays

* Harden provider installation and sign-in (#103)

* Harden provider installation and sign-in

* Fix Windows provider runtime test fixtures

* Make Windows PATH test path-stable

* Close provider onboarding reliability gaps

* Keep post-install sign-in recovery on the correct path

* Canonicalize Windows runtime discovery test paths

* Harden provider device-code recovery

* Harden OpenCode and Kilo turn completion (#120)

* Harden OpenCode and Kilo turn completion

* fix(provider): isolate OpenCode turn completion ownership

* fix(provider): close OpenCode completion review races

* fix(provider): fence OpenCode reply and replay races

* fix(provider): clean interrupted OpenCode replies

* fix(provider): harden OpenCode interaction ownership

* fix(provider): fail closed on ambiguous replies

* Harden OpenCode lifecycle retirement

* Serialize OpenCode session retirement

* Make OpenCode retirement interruption safe

* Finalize confirmed OpenCode process exits

* Add native folder drop to Add Project (#115)

* feat(projects): add native folder drop intake

* fix(projects): harden folder drop feedback

* fix(projects): keep folder errors visible

* fix(projects): preserve compact folder dialog footer

* fix(projects): harden native folder intake

* docs(qa): align folder intake evidence

* fix(projects): scope folder drop to dialog

* test(projects): cover platform folder labels

* docs: correct folder drop verification evidence

* docs: qualify native drag evidence

* docs: refresh folder drop verification evidence

* docs: refresh folder drop certification evidence

* docs: recertify folder drop on latest main

* Neutralize project drops outside dialog

* Update folder drop acceptance evidence

* Make new thread workspace intent explicit (#118)

* fix(web): make new thread workspace intent explicit

* fix(web): serialize distinct new thread intents

* test(web): type exact workspace branch mocks

* fix(web): preserve new thread request ordering

* fix(web): preserve latest new thread intent

* fix(web): coordinate all new thread navigation

* fix(web): preserve latest navigation across preparation

* fix(web): close remaining navigation races

* chore: clean merged sidebar imports

* fix(web): close terminal and route ownership gaps

* fix(web): coordinate every new-thread route intent

* fix(web): enforce route ownership before history commits

* test(web): use typed routes in navigation guard proof

* fix(web): release committed navigation ownership

* docs: add Scient 0.5.13 release notes

* chore: keep promotion tree aligned with main

* chore: restore test cleanup in promotion tree

* chore: align promotion test tree
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant