From 7e76961da10549582f17756f27e6d3ff16653a4f Mon Sep 17 00:00:00 2001 From: Daniel Stenborg <81319116+StDl71@users.noreply.github.com> Date: Sat, 29 Aug 2026 10:05:32 +0200 Subject: [PATCH] fix(inbox): preview underlag via the inline document proxy (#1753) Dokumentinkorgen previews PDFs and images through the same-origin /api/documents/:id/inline proxy instead of the Supabase signed URL, which Chrome blocks in a frame (Content-Disposition: attachment). HTML underlag already used the proxy. Co-authored-by: Daniel Stenborg --- .../general/InvoiceInboxWorkspace.tsx | 19 +++++-------------- 1 file changed, 5 insertions(+), 14 deletions(-) diff --git a/components/extensions/general/InvoiceInboxWorkspace.tsx b/components/extensions/general/InvoiceInboxWorkspace.tsx index b53f57d4..bdd7668c 100644 --- a/components/extensions/general/InvoiceInboxWorkspace.tsx +++ b/components/extensions/general/InvoiceInboxWorkspace.tsx @@ -786,19 +786,10 @@ export default function InvoiceInboxWorkspace(_props: WorkspaceComponentProps) { } const { data } = await res.json() if (docRequestRef.current !== request) return - const url: string | null = data?.download_url ?? null - // HTML mail underlag renders via the same-origin inline proxy: it - // serves text/html with a CSP sandbox header and guaranteed inline - // disposition. Other types keep the signed storage URL. - const effectiveUrl = - data?.mime_type === 'text/html' ? `/api/documents/${documentId}/inline` : url - if (!url) { - // The document row exists but no signed URL came back: still a load - // failure, not an absent underlag. - setDocState('error') - return - } - setDocUrl(effectiveUrl) + // Always preview via the same-origin inline proxy. Signed Storage URLs + // are served as Content-Disposition: attachment, which Chrome blocks in + // iframe/img with "Det här innehållet har blockerats". + setDocUrl(`/api/documents/${documentId}/inline`) setDocMime(data?.mime_type ?? null) setDocState('ready') } catch { @@ -2326,7 +2317,7 @@ export function DocumentPreview({ ) : ( // PDF: iframe needs explicit height, frame fills the available pane.
-