Skip to content

Admit sandboxed webview downloads through bounded typed leases #535

Description

@wieslawsoltes

Parent: #268. Webview epic: #264. Release epic: #227. Host consumers: AppScene #32/#123.

Proven gap

Nested download anchors need browser-shaped sandbox and activation admission plus a typed transfer boundary. Existing behavior falls through legacy save/JSON paths, does not require allow-downloads through every sandboxed owner, and cannot give AppScene immutable generation-stamped source data without also granting destination authority.

Focused implementation

  • Require native user activation within five seconds and allow-downloads on every sandboxed iframe ancestor.
  • Add a typed download request/lease carrying request ID, origin, document/frame generations, frame owner, target node, sanitized suggested name, MIME, exact/unknown size, and byte/URL/canvas source identity.
  • Keep destination choice, overwrite policy, filesystem grants, and large-file streaming in AppScene.
  • Support incremental host copying of immutable byte leases; release represents cancellation.
  • Cancel queued leases on top-level or owning-frame navigation while preserving taken generations for stale-host rejection.
  • Limit the queue to 16 requests, byte sources to 64 MiB per request and 64 MiB aggregate queued payload, names/origins to 4 KiB, MIME to 256 bytes, and URLs to 8 KiB.
  • Preserve exact Blob bytes/MIME and retained canvas identity; keep input[type=file] on its existing path.
  • Add native nested and file-service regression sources.

Acceptance and deferred gates

  • Implementation rebased on WebScene main 987b843076035ae86a6cb4279054ebdef79b0375.
  • Focused regression sources authored.
  • git diff --check passed.
  • Execute native/browser security and lifecycle contracts.
  • Implement/qualify AppScene destination UI, durable grants, errors, and large-file streaming.
  • Run exact unchanged-webview, performance, memory, package, and three-platform gates.

Execution is deferred under the current implementation-first direction.

Activity

  1. wieslawsoltes commented on Sep 19, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Completed by #536 and merged to WebScene main as e33fdbc6c11fd292070b5c8442568da39d39c57d. Download admission now requires recent native activation and allow-downloads; immutable typed leases retain origin/generations and bounded byte/URL/canvas sources without destination authority. Queued byte memory is capped at 64 MiB aggregate. Only git diff --check ran; AppScene #32/#123 and parent #268 own host consumption and cumulative evidence.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    vscode-oss/plannedPlanned for the AppScene/WebScene VS Code OSS integration

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions