Parent: #268. Webview epic: #264. Release epic: #227. Host consumers: AppScene #32/#123.
Proven gap
Nested download anchors need browser-shaped sandbox and activation admission plus a typed transfer boundary. Existing behavior falls through legacy save/JSON paths, does not require allow-downloads through every sandboxed owner, and cannot give AppScene immutable generation-stamped source data without also granting destination authority.
Focused implementation
- Require native user activation within five seconds and
allow-downloads on every sandboxed iframe ancestor.
- Add a typed download request/lease carrying request ID, origin, document/frame generations, frame owner, target node, sanitized suggested name, MIME, exact/unknown size, and byte/URL/canvas source identity.
- Keep destination choice, overwrite policy, filesystem grants, and large-file streaming in AppScene.
- Support incremental host copying of immutable byte leases; release represents cancellation.
- Cancel queued leases on top-level or owning-frame navigation while preserving taken generations for stale-host rejection.
- Limit the queue to 16 requests, byte sources to 64 MiB per request and 64 MiB aggregate queued payload, names/origins to 4 KiB, MIME to 256 bytes, and URLs to 8 KiB.
- Preserve exact Blob bytes/MIME and retained canvas identity; keep
input[type=file] on its existing path.
- Add native nested and file-service regression sources.
Acceptance and deferred gates
Execution is deferred under the current implementation-first direction.
Parent: #268. Webview epic: #264. Release epic: #227. Host consumers: AppScene #32/#123.
Proven gap
Nested download anchors need browser-shaped sandbox and activation admission plus a typed transfer boundary. Existing behavior falls through legacy save/JSON paths, does not require
allow-downloadsthrough every sandboxed owner, and cannot give AppScene immutable generation-stamped source data without also granting destination authority.Focused implementation
allow-downloadson every sandboxed iframe ancestor.input[type=file]on its existing path.Acceptance and deferred gates
987b843076035ae86a6cb4279054ebdef79b0375.git diff --checkpassed.Execution is deferred under the current implementation-first direction.