Files
amethyst/nappletHost/src/main
Claude d51484d538 fix(browser): close the gaps an audit found in download consent
- The saved file's MIME type now comes from the approved name, so
  MediaStore can't append a different extension than the card showed
  ("invoice.pdf" typed as an APK would have become "invoice.pdf.apk").
- File names drop bidi/zero-width/C1 characters, keep their extension
  when shortened, and render on one middle-ellipsized line.
- Refusals back off (1s, doubling to 1 min; Save resets), no card over
  another page dialog or permission prompt, and Save ignores taps for
  500 ms after the card appears.
- The card names the host a network file comes from when it isn't the
  page's (an ad frame, a CDN); a fresh about:blank popup falls back to
  it instead of silently dropping the download.
- Offers save at most once (no double file on a double tap); a decode
  failure (even OOM) refuses the download instead of killing :napplet;
  percent-decoding counts bytes before allocating; ;base64 must be the
  last parameter; more risky extensions.
- A closing embedded tab withdraws its card in the main process.
- The long-press data: save decodes off the main thread.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E3cqjbY7FX2zrkGXCVXpFD
2026-09-30 19:54:22 +00:00
..