Skip to content

File Viewer v2.3.1

Choose a tag to compare

@wybaby168 wybaby168 released this 24 Aug 13:38

File Viewer v2.3.1 hardens the legacy DOC rendering boundary without changing the format matrix or public integration APIs.

  • Encodes document-controlled font, link, image, and attachment markup before it reaches the direct HTML API.
  • Blocks external DOC links by default while preserving internal bookmarks. Explicit allow mode accepts only HTTP(S), mail, telephone, and safe relative links.
  • Adds defense-in-depth sanitization at the viewer mount boundary and keeps DOC sanitization in its lazy renderer chunk.
  • Extends browser regression coverage for direct HTML output and mounted rendering.

Published fixes include @file-viewer/doc@2.3.1, msdoc-viewer@0.2.2, @file-viewer/renderer-word@2.3.2, and the 2.3.4 Office, Full, and copy-assets patch line.

All 57 registry tarballs, 12,434 packaged file entries, the asset-copy CLI, and a cold Full-package installation were verified after publication.