feat: require explicit downloads for received files - #25
Open
SamOkampo wants to merge 1 commit into
Open
Conversation
SamOkampo
marked this pull request as ready for review
August 4, 2026 07:35
|
ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Changes the receiver experience so files received in memory are not downloaded automatically.
Each received file now remains available until the receiver explicitly chooses to download it.
New receiver flow
Multiple files
The previous implementation retained only one active Blob URL.
The new implementation:
Delivery semantics preserved
The receiver still:
The sender does not wait for the receiver to click Download.
No changes were made to:
Direct-to-disk behavior
Browsers using direct-to-disk mode preserve the existing behavior.
No Blob URL or extra download button is created when the file has already been saved directly to disk.
Cleanup
Pending Blob URLs are released on:
The bfcache behavior is preserved:
Analytics
Adds:
receiver_download_clicked
Only these properties are permitted:
No file names, sizes, MIME values, Blob URLs, room codes or internal identifiers are collected.
Validation
Remaining validation
Physical testing is still required on:
The main remaining risk is memory pressure when several large files remain pending in mobile memory.