Skip to content

fix(view): let the package iframe start downloads (allow-downloads) - #161

Merged
erseco merged 1 commit into
mainfrom
hotfix/allow-downloads-in-package-iframe
Sep 29, 2026
Merged

erseco merged 1 commit into
mainfrom
hotfix/allow-downloads-in-package-iframe

Conversation

@erseco

@erseco erseco commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Refs exelearning/exelearning#2488. Related: exelearning/exelearning#2489, exelearning/omeka-s-exelearning#63, exelearning/wp-exelearning#156.

Thanks to smorros for reporting the original issue and to @biyayo for forwarding it.

Problem

The package iframe in view.php is sandboxed without allow-downloads. Chrome (83+) and Firefox (82+) then silently drop every download the frame starts, with a console message like "Download is disallowed. The frame initiating or instantiating the download is sandboxed, but the flag 'allow-downloads' is not set". Two things are affected:

  • <a download> links authored in the package.
  • The download-source-file iDevice's "Download .elpx" button. It rebuilds the .elpx in the browser (refetch + fflate), and the progress bar completes, but no file is ever saved.

I reproduced the drop in Chrome on the Omeka S module, which has the same sandbox without allow-downloads. There the rebuild finished and Chrome logged the message above.

Why not intercept like Omeka and WordPress

In Omeka S and WordPress, the in-content button is routed to the original upload, because those embeds already offer that file publicly. I did not do that here. The original lives in the package file area, and exelearning_pluginfile() limits it to moodle/course:manageactivities ("Only teachers can download the full ELPX package", lib.php:545-557). Serving it to students would change the permission model.

The in-browser rebuild only packs what the learner can already see. Moodle sends no CSP for pluginfile.php, so fflate's blob: workers are not blocked here: the "Processing... 100%" hang from #2488 does not happen. The missing sandbox flag is the only thing stopping the download.

Change

  • view.php: add allow-downloads to the package iframe sandbox, with the rationale next to the code.
    • It grants no new capability: with allow-same-origin + allow-scripts, package script can already start a download through the parent (TRACKING threat 8).
    • allow-top-navigation and allow-modals stay blocked.
  • tests/behat/mod_exelearning.feature: a server-rendered scenario (no @javascript) asserts that the sandbox contains allow-downloads and still omits allow-top-navigation and allow-modals.
  • docs/TRACKING.md: documents the flag, fixes the stale view.php line reference in threat 8, and notes that any future content CSP (DEC-0-16 M3) must allow worker-src 'self' blob:.
  • version.php: 2026092610 → 2026092900 (release = 'dev').

Verification

  • vendor/bin/phpcs --standard=moodle view.php version.php reports 0 errors and 0 warnings; php -l view.php is clean.
  • make check-version → OK (development). make architecture-check → OK.
  • Behat was not run locally: this machine has no Moodle environment. The new scenario runs in CI (moodle-plugin-ci behat).

Moodle Playground Preview

The changes in this pull request can be previewed and tested using a Moodle Playground instance.

Preview in Moodle Playground

ℹ️ The eXeLearning editor is fetched from the shared release and unpacked into the plugin when the playground boots, so the first load may take a few extra seconds. ELPX upload, viewer and preview work normally.

Without allow-downloads the browser silently drops every download the
package frame starts: <a download> links and the download-source-file
iDevice's "Download .elpx" button, which rebuilds the package in the
browser (exelearning/exelearning#2488). Same-origin package script can
already download through the parent, so this grants no new capability.
@codecov-commenter

codecov-commenter commented Sep 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.92%. Comparing base (48a82fc) to head (b00b3c3).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff            @@
##               main     #161   +/-   ##
=========================================
  Coverage     93.92%   93.92%           
  Complexity      810      810           
=========================================
  Files            46       46           
  Lines          3554     3554           
=========================================
  Hits           3338     3338           
  Misses          216      216           
Flag Coverage Δ
javascript 96.00% <ø> (ø)
php 93.83% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

Components Coverage Δ
PHP (server-side) 93.83% <ø> (ø)
JavaScript (SCORM tracker) 96.00% <ø> (ø)
🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@erseco
erseco merged commit 938cda8 into main Sep 29, 2026
25 checks passed
@erseco
erseco deleted the hotfix/allow-downloads-in-package-iframe branch September 29, 2026 10:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants