8425f8286b
The first cut of the core ::preview consumer rendered the classic preview-attachment card — a button into the right rail we already had, which made the directive indistinguishable from an ordinary preview link. Now the directive shows the thing itself: the workspace HTML file renders in a sandboxed srcdoc iframe inline in the assistant message (opaque origin, allow-scripts only — no reach into the app, its storage, or the bridge), with an optional height attribute clamped to 120-1200px and the classic card kept below as the rail escape hatch. The frame waits for turn settle before reading the file (mid-stream it is often mid-write), resolves relative paths against the session's own cwd, and falls back to the plain card for non-HTML targets and remote gateways (no local file door there).