File Viewer v2.3.1
File Viewer v2.3.1 hardens the legacy DOC rendering boundary without changing the format matrix or public integration APIs.
- Encodes document-controlled font, link, image, and attachment markup before it reaches the direct HTML API.
- Blocks external DOC links by default while preserving internal bookmarks. Explicit allow mode accepts only HTTP(S), mail, telephone, and safe relative links.
- Adds defense-in-depth sanitization at the viewer mount boundary and keeps DOC sanitization in its lazy renderer chunk.
- Extends browser regression coverage for direct HTML output and mounted rendering.
Published fixes include @file-viewer/doc@2.3.1, msdoc-viewer@0.2.2, @file-viewer/renderer-word@2.3.2, and the 2.3.4 Office, Full, and copy-assets patch line.
All 57 registry tarballs, 12,434 packaged file entries, the asset-copy CLI, and a cold Full-package installation were verified after publication.