Pre-existing uncommitted work (auth dialog, provider profiles editor, runs route) preserved as baseline.
2.4 KiB
Office Preview
The workspace viewer renders DOCX files in the browser with docx-preview and
Excel Open XML files with SpreadJS. Supported browser-side spreadsheet formats
are XLSX, XLSM, XLTX, and XLTM. SpreadJS preserves workbook sheets, cell
formats, formulas, merged ranges, and supported drawings more faithfully than a
data-table renderer. The browser surface is read-only: editing, pasting,
resizing, sheet reordering, and context menus are disabled.
Other supported Office files, and DOCX files that cannot be rendered in the browser, use a server-rendered PDF. The PDF is cached under the owning conversation's private runtime directory, keyed by the source extension and SHA-256. It is never added to the workspace file tree or shared across conversations.
Supported server-rendered input formats are DOC, DOCX, DOCM, DOTX, DOTM, XLS,
XLSX, XLSM, XLSB, XLTX, XLTM, and ODS. DOCX uses the browser-side
docx-preview renderer first, preserving document pages, fonts, and layout;
if it cannot render a file, the private PDF conversion is used. XLSX, XLSM,
XLTX, and XLTM use the browser-side SpreadJS renderer first. Legacy XLS, XLSB,
and ODS files continue to use the private PDF conversion.
SpreadJS is a commercial client-side dependency. Set a valid web deployment license before a production build:
NEXT_PUBLIC_SPREADJS_LICENSE_KEY=replace-with-your-spreadjs-web-license
The key is intentionally included in the browser bundle, so use a license issued for web distribution and never place an internal backend secret in this variable. Without a key, SpreadJS remains in evaluation mode for local testing.
Configure the converter in the WebUI server environment:
EVOSCIENTIST_OFFICE_PREVIEW_ENABLED=true
EVOSCIENTIST_OFFICE_PREVIEW_COMMAND=/usr/local/bin/soffice
EVOSCIENTIST_OFFICE_PREVIEW_CONCURRENCY=2
EVOSCIENTIST_OFFICE_PREVIEW_COMMAND is executed without a shell and receives
only fixed LibreOffice arguments plus a private temporary source copy. It is
still an external document converter: production deployments should point it
at a wrapper running with no network, a non-root user, a read-only source
mount, CPU/memory limits, and an execution timeout. Set
EVOSCIENTIST_OFFICE_PREVIEW_ENABLED=false when that isolation cannot be
provided; the viewer will still use the local DOCX and supported SpreadJS Excel
renderers, while legacy Office formats remain downloadable only.