feat(files): open markdown, HTML, and PDF files outside the workspace - #9140
Conversation
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
Bugbot Autofix is ON, but a cloud agent failed to start.
Reviewed by Cursor Bugbot for commit e52e413. Configure here.
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This PR adds an end-to-end capability for authenticated clients to read server-host files by absolute path and preview external HTML/PDF, changing filesystem and browser security boundaries across server, web, and mobile. The changed test also adds a file-level static-analysis diagnostic suppression, so the authorization expansion and analysis override require human review. You can add or adjust custom eligibility rules. Learn more. |
Agents often write reports to a temp directory and link them in chat. Those chips had no way to show the file: the files panel only accepted workspace-relative paths and the server rejected reads outside the root. The server now reads absolute host paths (writes stay workspace-only) and the media-file asset resource also serves HTML and PDF. Web and mobile open such chips in the file viewer read-only; PDFs use the integrated browser where it exists. Co-Authored-By: Claude Code <noreply@anthropic.com>
…le paths Co-Authored-By: Claude Code <noreply@anthropic.com>
e52e413 to
c1d8c40
Compare
…ed file Co-Authored-By: Claude Code <noreply@anthropic.com>
## What's Changed * perf(client-runtime): keep turn and checkpoint refs stable while streaming by @t3dotgg in pingdotgg/t3code#9145 * perf(clients): lease sidebar status by visibility by @StiensWout in pingdotgg/t3code#9052 * fix(desktop): show newest changes in nightly previews by @t3dotgg in pingdotgg/t3code#9138 * fix(settings): sync auto-settle and other shared preferences across environments by @t3dotgg in pingdotgg/t3code#9147 * fix(server): prevent accidental service downgrades by @t3dotgg in pingdotgg/t3code#5302 * fix(server): keep attachments until the command commits by @t3dotgg in pingdotgg/t3code#7941 * fix(claude): preview images read from the workspace by @t3dotgg in pingdotgg/t3code#9119 * fix(web): keep generated muted foreground dimmer than entered text by @flamboh in pingdotgg/t3code#9113 * fix(clients): stop repeating expanded commands by @t3dotgg in pingdotgg/t3code#9120 * fix(grok): health check, model selection, and stop all work against the real CLI by @t3dotgg in pingdotgg/t3code#9154 * perf(web): halve the cold-start bundle by splitting Clerk and cold routes by @StiensWout in pingdotgg/t3code#9058 * feat(desktop): update the desktop app on remote Macs from the Update button by @t3dotgg in pingdotgg/t3code#6554 * test(server): measure shell, second client, and reconnect transfer by @t3dotgg in pingdotgg/t3code#9157 * fix(web): project default model works on the hosted app by @juliusmarminge in pingdotgg/t3code#9142 * fix(web): darken neutral control surfaces by @maria-rcks in pingdotgg/t3code#9064 * fix(web): preserve panel state across workspace refreshes by @maria-rcks in pingdotgg/t3code#8968 * feat(files): open markdown, HTML, and PDF files outside the workspace by @juliusmarminge in pingdotgg/t3code#9140 * feat(web): render HTML and PDF files in the file viewer by @juliusmarminge in pingdotgg/t3code#9143 * fix(web): compact project settings actions by @maria-rcks in pingdotgg/t3code#9160 * fix(web): browse folders from file breadcrumbs by @404khai in pingdotgg/t3code#8910 ## New Contributors * @404khai made their first contribution in pingdotgg/t3code#8910 **Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260902.1252...v0.0.39-nightly.20260902.1253 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260902.1253

Agents regularly write a report to a temp directory and link it in their reply. That chip was a dead end: the files panel only accepted workspace-relative paths, and
projects.readFilerejected anything outside the root. HTML and PDF links outside the workspace failed one layer down, because the browser preview always minted a workspace-scoped asset URL.How
WorkspaceFileSystem.readFileaccepts an absolute path and reads that host file in place. Workspace-relative paths keep the root and symlink containment checks, andwriteFilestill rejects absolute paths, so host files are read-only. Themedia-fileasset resource now also accepts.html,.htm, and.pdf, using the same exact-file, inode-pinned token; workspace HTML keeps using the directory-scopedworkspace-fileresource so sibling assets load.panelPaththat falls back to the absolute host path for non-media files outside the workspace, so they open in the files panel. The panel renders host files read-only (rendered Markdown works, checkboxes do not write back) with breadcrumbs starting at the filesystem root.openFileInPreviewpicksworkspace-fileormedia-fileby workspace membership, so the panel's browser button and PDF chips work for host files.media-fileresource), and the asset URL hook picksmedia-filefor host paths.composer.md;environment-auth.mdupdated, since it explicitly stated the workspace boundary still applied to HTML and PDF.No wire changes:
media-fileandreadFilekeep their shapes, so older clients keep working.One deliberate widening to flag: an authenticated
orchestration:readclient can now read any text file the server account can read, not only workspace files. That matches whatfilesystem.browseandmedia-filealready allow and is documented as such.Demo
Clicking a
/tmp/...cleanup-report.mdchip opens it in the files panel, toggling to rendered Markdown, then opening the.htmlchip beside it:https://gh-file-drop-api-prod-mi5fy3sowv63ufte.pinglabs.workers.dev/f/7191626f13944a44/outside-workspace-files.webm
Verification
apps/server:WorkspaceFileSystem.test.ts(absolute read, absolute write rejected),AssetAccess.test.ts(HTML/PDF minting),http.test.tsapps/web:filePath.test.ts(host breadcrumbs),markdown-links.test.ts,ChatMarkdown.*.test.tsx,FilePreviewPanel.test.tsapps/mobile:filePath.test.ts(route segments round-trip)Written by Claude Fable 5 in Claude Code.
🤖 Generated with Claude Code
Note
Medium Risk
Expands what authenticated
orchestration:readclients can read and preview on the host (any text file via absolutereadFile, HTML/PDF viamedia-file), though writes stay workspace-bound and HTML gets a sandbox CSP.Overview
Agents can link files outside the project (e.g.
/tmp/.../report.md); this PR wires those links through end-to-end instead of stopping at workspace-only paths.Server:
projects.readFile/WorkspaceFileSystem.readFilenow accept an absolute host path and read that file in place (still read-only—writeFilerejects absolutes). Workspace-relative reads keep root/symlink containment; opens use non-blocking mode so FIFOs fail instead of hanging. Themedia-fileasset resource now allows HTML and PDF (viahostPreviewMimeTypeFromExtension), and inline HTML responses add a sandbox CSP.Web & mobile: File chips carry a
panelPaththat can be the absolute host path; the files panel shows host files read-only (markdown render on, task-list edits off) with breadcrumbs from the filesystem root.openFileInPreviewand asset URL minting chooseworkspace-filevsmedia-filebased on whether the path is inside the workspace. Mobile thread links navigate to the file screen (or PDF preview) for absolute paths. Markdown relative links can anchor onimageBaseDirwhen rendering a file outside the repo.Docs/contracts: User and environment-auth docs describe host file read and expanded media preview; contract comments/error text updated—no wire shape changes.
Reviewed by Cursor Bugbot for commit c0fa311. Bugbot is set up for automated code reviews on this repo. Configure here.
Note
Support opening markdown, HTML, and PDF files outside the workspace
WorkspaceFileSystem.readFilenow accepts absolute host paths viaresolveReadTarget, resolving them throughrealpathwithout applying the workspace-root boundary check; writes remain workspace-relative only.AssetAccessaccept HTML and PDF (in addition to images and videos) using the new sharedhostPreviewMimeTypeFromExtensionclassifier; unsupported extensions still return no asset.baseDirso relative links anchor to the rendered file's directory rather than only the workspace cwd.WorkspaceFileSystem.resolveReadTargetbypasses the workspace-root boundary check for absolute reads — any reachable host file path is readable. HTML sandbox CSP permits scripts and forms within the sandboxed context; separately served HTML cannot load adjacent scripts, styles, or images.Macroscope summarized c0fa311.