feat: browser-side annotation screenshots for web preview
Capture the preview/browser iframe DOM with snapDOM (html-to-image fallback) so web annotation screenshots match the visible viewport, without a headless Chromium dependency. - Preserve document scroll via viewport crop and re-bake nested scroll (e.g. the Starlight sidebar) deterministically on the clone - Pin position:fixed elements to their measured viewport rect so headers and sidebars land correctly in the crop - Extract preview capture/proxy helpers into lib/preview/screenshot-capture.ts to slim down ContextPanel - Guard the external preview proxy against SSRF to private, loopback and reserved/link-local addresses (incl. cloud metadata) - Fully validate preview bridge messages before formatting/use - Warn on the empty browser tab that pages run with full access, so users browse untrusted sites knowingly
This commit is contained in:
@@ -1960,7 +1960,7 @@ export const Header: React.FC<HeaderProps> = ({
|
||||
onClick={toggleBottomTerminal}
|
||||
Icon={'terminal-box'}
|
||||
/>
|
||||
{hasElectronDesktopIPC ? (
|
||||
{!isMobile ? (
|
||||
<HeaderIconActionButton
|
||||
title={t('contextPanel.browser.open')}
|
||||
ariaLabel={t('contextPanel.browser.open')}
|
||||
|
||||
Reference in New Issue
Block a user