Parent: #267. Related: #264, #903.
Reproduced in installed unchanged Code OSS
The signed AppScene/WebScene Release from WebScene 5b4739c8, AppScene
36d7a82e and unchanged Code OSS 645f29cc loads the virtual-HTTPS
Markdown prelude. Its nested iframe is owned by that prelude document and
authored as ./fake.html?id=.... In a bounded main-realm native probe,
frame.ownerDocument.baseURI is the virtual-HTTPS prelude URL, while
reading frame.src returns a loopback http://127.0.0.1:<port>/fake.html.
The authored attribute remains relative. Evidence is recorded in
vscode-demo/docs/validation/markdown-preview-layout-20260921.md and
build/appscene-webview-398/native-preview-36d7a82-final-diagnostic.log.
webscene_v8_runtime_dom_properties.inc::get_element_url resolves reflected
src/href against current_base_address(), which selects the caller's
document. Other owner-sensitive paths use effective_document_base and
css_cascade_root_for_node. This observation does not prove the actual
nested navigation requested the wrong origin; that request has a separate
resolution path.
Proposed focused fix and gates
Resolve URL-valued element properties against the element's owning document
base, including same-origin cross-document reads and <base> changes. Keep
getAttribute authored, navigation request URLs and cross-origin access
policy separate. Add a browser-referenced nested relative iframe.src,
img.src, and a.href contract, plus native direct caller/owner realm,
detached node, base mutation, and virtual-origin checks. Compare Chromium
before/after; ensure no additional resource requests or retained documents.
Then rerun unchanged Markdown preview; do not close webview acceptance until
its content paints and passes layout/security/lifecycle/performance gates.
Parent: #267. Related: #264, #903.
Reproduced in installed unchanged Code OSS
The signed AppScene/WebScene Release from WebScene
5b4739c8, AppScene36d7a82eand unchanged Code OSS645f29ccloads the virtual-HTTPSMarkdown prelude. Its nested iframe is owned by that prelude document and
authored as
./fake.html?id=.... In a bounded main-realm native probe,frame.ownerDocument.baseURIis the virtual-HTTPS prelude URL, whilereading
frame.srcreturns a loopbackhttp://127.0.0.1:<port>/fake.html.The authored attribute remains relative. Evidence is recorded in
vscode-demo/docs/validation/markdown-preview-layout-20260921.mdandbuild/appscene-webview-398/native-preview-36d7a82-final-diagnostic.log.webscene_v8_runtime_dom_properties.inc::get_element_urlresolves reflectedsrc/hrefagainstcurrent_base_address(), which selects the caller'sdocument. Other owner-sensitive paths use
effective_document_baseandcss_cascade_root_for_node. This observation does not prove the actualnested navigation requested the wrong origin; that request has a separate
resolution path.
Proposed focused fix and gates
Resolve URL-valued element properties against the element's owning document
base, including same-origin cross-document reads and
<base>changes. KeepgetAttributeauthored, navigation request URLs and cross-origin accesspolicy separate. Add a browser-referenced nested relative
iframe.src,img.src, anda.hrefcontract, plus native direct caller/owner realm,detached node, base mutation, and virtual-origin checks. Compare Chromium
before/after; ensure no additional resource requests or retained documents.
Then rerun unchanged Markdown preview; do not close webview acceptance until
its content paints and passes layout/security/lifecycle/performance gates.