1.5.1: declare the widget CSP in ChatGPT's own key - #35
Merged
Merged
Conversation
In ChatGPT an Instagram reel's widget showed the ▶ placeholder instead of its thumbnail, under an orange "CSP off" badge. ChatGPT reads a widget's policy only from openai/widgetCSP (snake_case connect_domains / resource_domains); a resource carrying only the standard ui.csp, as ours did, gets no policy there. Claude reads ui.csp and shows the thumbnail. NimbleBrain measured the same on 2026-09-17 (NimbleBrainInc/synapse#100). Every widget resource now carries both keys from one constant, so the two lists cannot drift. connect_domains is empty: the widgets fetch nothing and reach the server through the host. redirect_domains is left out, since ChatGPT appends ?redirectUrl= to links on the domains it lists. The changelog also moves the two track-name fixes from Unreleased into 1.5.0, where they shipped, and dates 1.5.0 by its tag. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ChatGPT reads the CSP of a widget only from
_meta["openai/widgetCSP"]. Our widget resources declared only the standard_meta.ui.csp. This PR adds the ChatGPT key, with the same 15 domains, to all four widget resources.The problem
In ChatGPT, the transcript widget for an Instagram reel showed the ▶ placeholder instead of the thumbnail. Claude reads
ui.csp, and in Claude the same thumbnail loads.Two investigations read the real host code and reproduced both hosts in headless Chrome:
ui.csp.resourceDomainsintoimg-srcas written, wildcards included. The Instagram thumbnail loads.widgetResponse.csp) or fromchatgpt_sdk.csp, in the snake_case form ofopenai/widgetCSP. A declared CSP is "trusted": the sandbox copies each entry, wildcards included, intoimg-src.img-src 'self' data:plus a fixed OpenAI list. This default blocks every external thumbnail,i.ytimg.comincluded.ONLY_ME) gets no policy at all, unless the account setting "enforce CSP in dev mode" is on.ui.cspalone no policy (NimbleBrainInc/synapse#100). As a result, the published Transcriptor app most probably shows no thumbnails for any platform today.Changes
WIDGET_CSP_META, holds both keys. The four resources spread it, so the two lists cannot drift.connect_domainsis empty. The widgets fetch nothing themselves. They reach the server through the host.redirect_domainsis not set. ChatGPT appends?redirectUrl=to links on the domains in that list, so the "Open" links to Instagram and YouTube would change.[Unreleased]into 1.5.0, because they shipped in 1.5.0. The date of 1.5.0 is now the date of its tag.What this PR does not settle
The orange "CSP off" badge in the screenshot does not describe the widget. ChatGPT shows it for every developer-mode app when "enforce CSP" is off. In that mode, with no CSP, the reproduction loads the Instagram thumbnail. So in the developer-mode test, something other than the CSP probably blocked the image: for example a browser extension that blocks
cdninstagram.com. The console message of the failed image tells which:net::ERR_BLOCKED_BY_CLIENT: an extension.Side effects
connect-src 'self'plus the OpenAI list, andframe-src 'none'. The four built widgets started with no CSP violations under this policy.ui://URIs do not change in this PR, because a new URI changes the tool metadata of the published app.Checks
make check-no-smokepasses: 12 suites, 320 tests.After the merge
v1.5.1tag on the merge commit, and wait forpublish-dockerand Watchtower.resources/readinside the container, and make sure that each widget resource hasopenai/widgetCSP.🤖 Generated with Claude Code