fix(export): let the keepsake download through X-Frame-Options on iOS
The keepsake download navigates a hidden, same-origin iframe (deliberately: a top-level navigation to a 404/429 would unload the PWA). Caddy stamped a site-wide `X-Frame-Options: DENY` that also covered the proxied `/api/*`. Blink hands a `Content-Disposition: attachment` response to the download manager at the network layer, so Chromium never noticed. WebKit enforces XFO on the frame navigation first and aborts the load — so on iOS Safari, the app's primary platform, tapping Download did nothing at all, silently. Carve the two export endpoints out to SAMEORIGIN, which still blocks cross-origin framing. Implemented as two disjoint matchers rather than an override: Caddy applies the FIRST `header` directive outermost, so it wins on write and a later, more specific `header` is silently ignored (verified against the running test stack). Also close the test gap that let this ship: - `06-export` ran on chromium-desktop only; add it to `webkit-iphone`, the only engine that enforces XFO on the download frame. - No test in the suite ever clicked a download button — every archive assertion used Node `fetch`, which has no frame and no XFO enforcement. Add a spec that clicks it and awaits a real `download` event. Verified falsifiable: with the blanket DENY reinstated it fails and reports the WebKit refusal as the cause. - Fix `ExportPage`'s card-scoped locators, which matched nothing: the cards carry `class="card p-5"` (a Tailwind `@apply` component class), never the `rounded-xl` the page object looked for. This had left the "shows enabled download buttons" test red on main. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -37,12 +37,19 @@ export class ExportPage {
|
||||
/**
|
||||
* The "Download" button inside the card whose heading is `heading`.
|
||||
*
|
||||
* Scoped to the card element (`div.rounded-xl`) rather than "any div containing the
|
||||
* heading" — the latter also matches the page wrapper, which contains BOTH cards' buttons.
|
||||
* Scoped to the card element rather than "any div containing the heading" — the latter
|
||||
* also matches the page wrapper, which contains BOTH cards' buttons.
|
||||
*
|
||||
* The scope class is `div.card` (see the ZIP/HTML cards in
|
||||
* frontend/src/routes/export/+page.svelte). It was previously `div.rounded-xl`, which
|
||||
* matched NOTHING: `.card` is a Tailwind `@apply` component class
|
||||
* (frontend/src/lib/styles/components.css) so the DOM only ever carries `class="card p-5"`
|
||||
* — and the utility it applies is `rounded-2xl` anyway. Both card-scoped locators were
|
||||
* therefore dead, which is why the "shows enabled download buttons" test was red.
|
||||
*/
|
||||
private cardButton(heading: string): Locator {
|
||||
return this.page
|
||||
.locator('div.rounded-xl')
|
||||
.locator('div.card')
|
||||
.filter({ has: this.page.getByRole('heading', { name: heading, exact: true }) })
|
||||
.getByRole('button', { name: 'Download', exact: true });
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user