fix(inbox): preview underlag via the inline document proxy (#1753)

Dokumentinkorgen previews PDFs and images through the same-origin /api/documents/:id/inline proxy instead of the Supabase signed URL, which Chrome blocks in a frame (Content-Disposition: attachment). HTML underlag already used the proxy.

Co-authored-by: Daniel Stenborg <daniel@stenborg.se>
This commit is contained in:
Daniel Stenborg
2026-08-29 10:05:32 +02:00
committed by GitHub
co-authored by Daniel Stenborg
parent 338ac4e913
commit 7e76961da1
@@ -786,19 +786,10 @@ export default function InvoiceInboxWorkspace(_props: WorkspaceComponentProps) {
}
const { data } = await res.json()
if (docRequestRef.current !== request) return
const url: string | null = data?.download_url ?? null
// HTML mail underlag renders via the same-origin inline proxy: it
// serves text/html with a CSP sandbox header and guaranteed inline
// disposition. Other types keep the signed storage URL.
const effectiveUrl =
data?.mime_type === 'text/html' ? `/api/documents/${documentId}/inline` : url
if (!url) {
// The document row exists but no signed URL came back: still a load
// failure, not an absent underlag.
setDocState('error')
return
}
setDocUrl(effectiveUrl)
// Always preview via the same-origin inline proxy. Signed Storage URLs
// are served as Content-Disposition: attachment, which Chrome blocks in
// iframe/img with "Det här innehållet har blockerats".
setDocUrl(`/api/documents/${documentId}/inline`)
setDocMime(data?.mime_type ?? null)
setDocState('ready')
} catch {
@@ -2326,7 +2317,7 @@ export function DocumentPreview({
) : (
// PDF: iframe needs explicit height, frame fills the available pane.
<div className="h-full w-full max-w-3xl bg-background rounded-lg border overflow-hidden">
<iframe src={docUrl} className="w-full h-full border-0" title="Underlag" />
<embed src={docUrl} type="application/pdf" className="w-full h-full border-0" title="Underlag" />
</div>
)}
</div>