Skip to content

fix(opencode): allow blob frames and objects in embedded UI CSP - #51636

Open
Serenity-2026 wants to merge 1 commit into
anomalyco:devfrom
Serenity-2026:fix-embedded-ui-csp
Open

Serenity-2026 wants to merge 1 commit into
anomalyco:devfrom
Serenity-2026:fix-embedded-ui-csp

Conversation

@Serenity-2026

@Serenity-2026 Serenity-2026 commented Sep 27, 2026 •

Copy link
Copy Markdown

Issue for this PR

Closes #50828

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

The embedded web UI CSP had no frame-src or object-src directive, so blob: iframes and objects fell back to default-src 'self' and were blocked. The icon renderer frames blob: URLs, so affected icons showed the browser's blocked-content placeholder; PDF previews are blocked the same way (#52591). Added frame-src 'self' blob: and object-src 'self' blob:. img-src and connect-src already allowed blob:.

How did you verify your code works?

Added packages/opencode/test/server/ui-csp.test.ts asserting the generated policy (with and without a theme-preload hash) contains both directives. From packages/opencode: bun test test/server/ui-csp.test.ts and bun run typecheck.

Screenshots / recordings

CSP header change:

before: ... media-src 'self' data:; connect-src * data: blob:
after: ... media-src 'self' data:; frame-src 'self' blob:; object-src 'self' blob:; connect-src * data: blob:

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

If you do not follow this template your PR will be automatically rejected.

@github-actions github-actions Bot added the needs:compliance This means the issue will auto-close after 2 hours. label Sep 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

The following comment was made by an LLM, it may be inaccurate:

@github-actions github-actions Bot removed the needs:compliance This means the issue will auto-close after 2 hours. label Sep 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thanks for updating your PR! It now meets our contributing guidelines. 👍

@jianzhangg

Copy link
Copy Markdown

Thanks for this — the diagnosis matches exactly what I see on 2.0.21 (HTML file preview blocked with the frame-src-fallback error; details and console excerpt in #50828).

One suggestion so this closes the whole family: #52591 (closed as duplicate of #50828) reports PDF preview blocked as well, and its title notes object-src is missing too. If the PDF plugin document inside the blob: iframe is subject to object-src, adding object-src 'self' blob: alongside frame-src 'self' blob: (plus a test assertion) would let this PR close both #50828 and #52591 in one go.

Happy to test a build with the change on macOS + Chrome if useful.

The embedded web UI CSP had no frame-src or object-src directive, so blob:
iframes and objects fell back to default-src 'self' and were blocked. The icon
renderer frames blob: URLs (icons showed the browser's blocked placeholder),
and PDF previews are affected the same way. Add frame-src 'self' blob: and
object-src 'self' blob:.

Closes anomalyco#50828
@Serenity-2026
Serenity-2026 force-pushed the fix-embedded-ui-csp branch 2 times, most recently from d02f9c5 to cbaf017 Compare October 2, 2026 15:34
@Serenity-2026

Copy link
Copy Markdown
Author

Done — added object-src 'self' blob: alongside frame-src 'self' blob: and asserted both in the test, so this should also cover the PDF case from #52591. A test build on your side would be welcome.

@Serenity-2026 Serenity-2026 changed the title fix(opencode): allow blob frames in embedded UI CSP fix(opencode): allow blob frames and objects in embedded UI CSP Oct 2, 2026
@jianzhangg

Copy link
Copy Markdown

Heads-up before this merges: the fix needs to land on the v2 branch too, otherwise it will not fix the shipping desktop build.

The CSP string has a second copy on v2 that is identical and has no frame-src/object-src:

  • dev: packages/opencode/src/server/shared/ui.ts (patched by this PR)
  • v2: packages/cli/src/services/web-ui.ts:62 (unchanged)

Desktop 2.0.22 is built from refs/heads/v2 (see the release metadata) and serves CSP from that file, so I can still reproduce the blocked blob: preview iframe there:

content-security-policy: default-src 'self'; script-src 'self' 'wasm-unsafe-eval' 'sha256-...'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https: blob:; font-src 'self' data:; media-src 'self' data:; connect-src * data: blob:

Could you apply the same frame-src 'self' blob:; object-src 'self' blob: change to packages/cli/src/services/web-ui.ts (base v2), or keep both files in this PR? Extending the test to assert both call sites would keep them from drifting again. Thanks!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

web-ui: CSP missing frame-src blocks blob: iframes ("This content is blocked")

2 participants