Skip to content

fix(desktop): route remote media through native network boundary - #32

Merged
avabbbb merged 11 commits into
mainfrom
fix/desktop-native-media-fetch
Sep 29, 2026
Merged

avabbbb merged 11 commits into
mainfrom
fix/desktop-native-media-fetch

Conversation

@avabbbb

@avabbbb avabbbb commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Summary

Fixes a class of desktop-only failures caused by treating the Tauri WebView like a normal browser when downloading generated or historical remote media.

Root cause

Remote media was still materialized with browser fetch() and some downloads relied directly on <a download href="https://...">.

In the packaged desktop app that means:

  • generated media can play as a remote URL but fail to persist locally;
  • WebView CORS can reject the Blob fetch;
  • old remote-only nodes can fail to load/export/download;
  • the download attribute is not a reliable cross-origin desktop save path.

Native media boundary

Adds a bounded Rust command backed by the existing reqwest dependency:

HTTPS remote URL
→ Rust reqwest
→ redirect + address validation
→ content-length / actual-size limit
→ raw Tauri IPC ArrayBuffer
→ Blob
→ normal Iris local media flow

The command:

  • allows HTTPS only;
  • rejects embedded URL credentials;
  • rejects non-443 explicit ports;
  • rejects localhost, .local, .internal and private/special IP targets;
  • revalidates every redirect;
  • caps redirects at 5;
  • caps downloads at 256 MiB;
  • uses connect + overall timeouts.

Raw media bytes return through tauri::ipc::Response, avoiding JSON/base64 or number[] encoding for large files.

Product paths fixed

  • workflowGeneration.ts

    • generated image/video result download now uses the native boundary in Tauri;
    • successful results continue into the existing IndexedDB/local workflow media ingest path.
  • components/workflow/media.ts

    • old remote-only HTTPS nodes now materialize through native fetch in Tauri;
    • preview uses a Blob URL instead of relying on remote <video src=https://...> behavior;
    • browser builds continue to use normal fetch().
  • StudioMediaBrowser.tsx

    • download is Blob-first rather than direct cross-origin <a download>;
    • if native retrieval fails for a remote HTTPS URL, Iris asks the existing Tauri opener backend to open the source URL in the system browser instead of silently doing nothing.

Deliberately not included

This PR does not migrate every Provider API call to Rust.

Provider submit/poll/upload routes remain separate work because they may require provider-specific auth, proxy and BYOK behavior. This PR only establishes the P0 media-download boundary that directly caused packaged EXE media failures.

Tests

Adds JS coverage for:

  • native HTTPS routing;
  • raw IPC frame decoding;
  • excluding blob/data URLs from native routing;
  • system-browser fallback command;
  • malformed response rejection.

Adds Rust unit coverage for:

  • non-HTTPS/private/localhost rejection;
  • raw media frame format.

Hosted CI / Rust / Desktop packaging should validate the final integration.

@avabbbb
avabbbb merged commit 231d90c into main Sep 29, 2026
18 checks passed
@avabbbb
avabbbb deleted the fix/desktop-native-media-fetch branch September 29, 2026 02:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant