mirror of
https://github.com/hcengineering/platform.git
synced 2026-10-01 14:05:05 +02:00
fix: embed pdf via direct link (#10491)
Signed-off-by: Alexander Onnikov <Alexander.Onnikov@xored.com>
This commit is contained in:
@@ -14,29 +14,11 @@
|
||||
-->
|
||||
|
||||
<script lang="ts">
|
||||
import { onDestroy } from 'svelte'
|
||||
import Loading from './Loading.svelte'
|
||||
|
||||
export let src: string
|
||||
export let name: string
|
||||
export let fit: boolean = false
|
||||
export let css: string | undefined = undefined
|
||||
|
||||
let iframeSrc: string | undefined = undefined
|
||||
|
||||
async function loadFile (src: string): Promise<void> {
|
||||
if (iframeSrc !== undefined) {
|
||||
URL.revokeObjectURL(iframeSrc)
|
||||
iframeSrc = undefined
|
||||
}
|
||||
|
||||
const response = await fetch(src)
|
||||
const blob = await response.blob()
|
||||
iframeSrc = URL.createObjectURL(blob)
|
||||
}
|
||||
|
||||
$: void loadFile(src)
|
||||
|
||||
let iframe: HTMLIFrameElement | undefined = undefined
|
||||
|
||||
// eslint-disable-next-line @typescript-eslint/prefer-optional-chain
|
||||
@@ -58,19 +40,9 @@
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
onDestroy(() => {
|
||||
if (iframeSrc !== undefined) {
|
||||
URL.revokeObjectURL(iframeSrc)
|
||||
}
|
||||
})
|
||||
</script>
|
||||
|
||||
{#if iframeSrc}
|
||||
<iframe bind:this={iframe} class:fit src={iframeSrc + '#view=FitH&navpanes=0'} title={name} on:load />
|
||||
{:else}
|
||||
<Loading />
|
||||
{/if}
|
||||
<iframe bind:this={iframe} class:fit src={src + '#view=FitH&navpanes=0'} title={name} on:load />
|
||||
|
||||
<style lang="scss">
|
||||
iframe {
|
||||
|
||||
@@ -25,6 +25,8 @@ import { type Datalake, wrapETag } from '../datalake'
|
||||
import { getBufferSha256, getFileSha256 } from '../hash'
|
||||
import { type TemporaryDir } from '../tempdir'
|
||||
|
||||
const safeInlineTypes = ['application/pdf', 'image/png', 'image/jpeg', 'image/gif', 'image/webp']
|
||||
|
||||
interface BlobParentRequest {
|
||||
parent: string | null
|
||||
}
|
||||
@@ -76,13 +78,16 @@ export async function handleBlobGet (
|
||||
return
|
||||
}
|
||||
|
||||
const disposition = safeInlineTypes.includes(blob.contentType) ? 'inline' : 'attachment'
|
||||
|
||||
res.setHeader('Accept-Ranges', 'bytes')
|
||||
res.setHeader('Content-Length', blob.bodyLength.toString())
|
||||
res.setHeader('Content-Type', blob.contentType ?? '')
|
||||
res.setHeader('Content-Security-Policy', "default-src 'none';")
|
||||
res.setHeader('X-Content-Type-Options', 'nosniff')
|
||||
res.setHeader(
|
||||
'Content-Disposition',
|
||||
filename !== undefined ? `attachment; filename*=UTF-8''${encodeURIComponent(filename)}` : 'attachment'
|
||||
filename !== undefined ? `${disposition}; filename*=UTF-8''${encodeURIComponent(filename)}` : disposition
|
||||
)
|
||||
res.setHeader('Cache-Control', blob.cacheControl ?? cacheControl)
|
||||
res.setHeader('Last-Modified', new Date(blob.lastModified).toUTCString())
|
||||
@@ -131,13 +136,16 @@ export async function handleBlobHead (
|
||||
return
|
||||
}
|
||||
|
||||
const disposition = safeInlineTypes.includes(head.contentType) ? 'inline' : 'attachment'
|
||||
|
||||
res.setHeader('Accept-Ranges', 'bytes')
|
||||
res.setHeader('Content-Length', head.size.toString())
|
||||
res.setHeader('Content-Type', head.contentType ?? '')
|
||||
res.setHeader('Content-Security-Policy', "default-src 'none';")
|
||||
res.setHeader('X-Content-Type-Options', 'nosniff')
|
||||
res.setHeader(
|
||||
'Content-Disposition',
|
||||
filename !== undefined ? `attachment; filename*=UTF-8''${encodeURIComponent(filename)}` : 'attachment'
|
||||
filename !== undefined ? `${disposition}; filename*=UTF-8''${encodeURIComponent(filename)}` : disposition
|
||||
)
|
||||
res.setHeader('Cache-Control', head.cacheControl ?? cacheControl)
|
||||
res.setHeader('Last-Modified', new Date(head.lastModified).toUTCString())
|
||||
|
||||
Reference in New Issue
Block a user