Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 1 addition & 29 deletions packages/ui/src/components/EmbeddedPDF.svelte
Original file line number Diff line number Diff line change
Expand Up @@ -14,29 +14,11 @@
-->

<script lang="ts">
import { onDestroy } from 'svelte'
import Loading from './Loading.svelte'

export let src: string
export let name: string
export let fit: boolean = false
export let css: string | undefined = undefined

let iframeSrc: string | undefined = undefined

async function loadFile (src: string): Promise<void> {
if (iframeSrc !== undefined) {
URL.revokeObjectURL(iframeSrc)
iframeSrc = undefined
}

const response = await fetch(src)
const blob = await response.blob()
iframeSrc = URL.createObjectURL(blob)
}

$: void loadFile(src)

let iframe: HTMLIFrameElement | undefined = undefined

// eslint-disable-next-line @typescript-eslint/prefer-optional-chain
Expand All @@ -58,19 +40,9 @@
}
}
}

onDestroy(() => {
if (iframeSrc !== undefined) {
URL.revokeObjectURL(iframeSrc)
}
})
</script>

{#if iframeSrc}
<iframe bind:this={iframe} class:fit src={iframeSrc + '#view=FitH&navpanes=0'} title={name} on:load />
{:else}
<Loading />
{/if}
<iframe bind:this={iframe} class:fit src={src + '#view=FitH&navpanes=0'} title={name} on:load />

<style lang="scss">
iframe {
Expand Down
12 changes: 10 additions & 2 deletions services/datalake/pod-datalake/src/handlers/blob.ts
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,8 @@ import { type Datalake, wrapETag } from '../datalake'
import { getBufferSha256, getFileSha256 } from '../hash'
import { type TemporaryDir } from '../tempdir'

const safeInlineTypes = ['application/pdf', 'image/png', 'image/jpeg', 'image/gif', 'image/webp']

interface BlobParentRequest {
parent: string | null
}
Expand Down Expand Up @@ -76,13 +78,16 @@ export async function handleBlobGet (
return
}

const disposition = safeInlineTypes.includes(blob.contentType) ? 'inline' : 'attachment'

res.setHeader('Accept-Ranges', 'bytes')
res.setHeader('Content-Length', blob.bodyLength.toString())
res.setHeader('Content-Type', blob.contentType ?? '')
res.setHeader('Content-Security-Policy', "default-src 'none';")
res.setHeader('X-Content-Type-Options', 'nosniff')
res.setHeader(
'Content-Disposition',
filename !== undefined ? `attachment; filename*=UTF-8''${encodeURIComponent(filename)}` : 'attachment'
filename !== undefined ? `${disposition}; filename*=UTF-8''${encodeURIComponent(filename)}` : disposition
)
res.setHeader('Cache-Control', blob.cacheControl ?? cacheControl)
res.setHeader('Last-Modified', new Date(blob.lastModified).toUTCString())
Expand Down Expand Up @@ -131,13 +136,16 @@ export async function handleBlobHead (
return
}

const disposition = safeInlineTypes.includes(head.contentType) ? 'inline' : 'attachment'

res.setHeader('Accept-Ranges', 'bytes')
res.setHeader('Content-Length', head.size.toString())
res.setHeader('Content-Type', head.contentType ?? '')
res.setHeader('Content-Security-Policy', "default-src 'none';")
res.setHeader('X-Content-Type-Options', 'nosniff')
res.setHeader(
'Content-Disposition',
filename !== undefined ? `attachment; filename*=UTF-8''${encodeURIComponent(filename)}` : 'attachment'
filename !== undefined ? `${disposition}; filename*=UTF-8''${encodeURIComponent(filename)}` : disposition
)
res.setHeader('Cache-Control', head.cacheControl ?? cacheControl)
res.setHeader('Last-Modified', new Date(head.lastModified).toUTCString())
Expand Down
Loading