docs: clarify nosniff retention in html-preview spec
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
@@ -24,7 +24,7 @@ Workspace 文件对话框(`WorkspaceFileDialog.tsx`)打开 `.html` 文件时
|
||||
- `Content-Type: text/html; charset=utf-8`
|
||||
- `Content-Security-Policy: sandbox allow-scripts`(允许脚本;不授予 `allow-same-origin`,脚本运行在 opaque origin,无法读取应用 cookie/DOM,其 fetch 会被 API 的跨源与会话检查拒绝)
|
||||
- `Content-Disposition: inline`
|
||||
- 保留 `Cache-Control: no-store`;不加 `X-Content-Type-Options: nosniff` 以外的变化
|
||||
- 保留 `Cache-Control: no-store` 与 `X-Content-Type-Options: nosniff`
|
||||
- `?download=1` 优先于 `render=1`(仍为 attachment、text/plain)。
|
||||
- 非 render 模式行为完全不变(HTML 仍 text/plain + `sandbox`)。
|
||||
|
||||
|
||||
Reference in New Issue
Block a user