# 回帰 - クリックで PDF のダウンロードが開始される（新しいタブで開くべき）

**URL:** https://meta.discourse.org/t/regression-pdfs-download-initiated-on-click-should-be-open-in-new-tab/404910
**Category:** Bug
**Tags:** pdf-previews, fixed
**Created:** [2026 年 6 月 10 日午前 3:14 UTC](https://meta.discourse.org/t/regression-pdfs-download-initiated-on-click-should-be-open-in-new-tab/404910 "2026-06-10T03:14:15Z")
**Posts on this page:** 1
**Showing post:** 3

<div class="post-metadata">

### Author: ![zogstrip](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/zogstrip/32/512781_2.png) [@zogstrip](https://meta.discourse.org/u/zogstrip)
#### Post date: [2026 年 6 月 10 日午後 2:10 UTC](https://meta.discourse.org/t/regression-pdfs-download-initiated-on-click-should-be-open-in-new-tab/404910/3 "2026-06-10T14:10:34Z")

</div>

S3 を使用しているかどうかによって、`display` タイプが一貫していなかった問題です。これは以下の PR で修正されるはずです。

> <https://github.com/discourse/discourse/pull/40739>
>
> Inline-safe uploads (images, PDFs, audio and video) served from the local
> file s…tore were sent with \`Content-Disposition: attachment\`, so clicking a
> PDF link downloaded the file instead of opening it in the browser. This was
> inconsistent with the S3 store, which already serves these files inline, and
> it left simple self-hosted (single-container, no S3/CDN) sites unable to open
> PDFs inline.
> 
> \`UploadsController#send\_file\_local\_upload\` only set the disposition to
> \`attachment\` for unsafe types, and to \`inline\` when \`?inline=1\` was passed,
> leaving it unset otherwise. Rails' \`send\_file\` defaults an unset disposition
> to \`attachment\`, so inline-safe files fell through to a download.
> 
> Inline-safe files are now served with \`Content-Disposition: inline\` by
> default, mirroring the S3 store, while unsafe types (HTML, SVG, XML, ...) and
> explicit downloads (\`?dl=1\`) keep the \`attachment\` disposition. The redundant
> \`params\[:inline\]\` branch is removed, since inline-safe files are now inline by
> default.
> 
> The \`Content-Security-Policy: sandbox;\` header stays on \*\*every\*\* response as
> defense-in-depth: if the \`is\_inline\_safe?\` allowlist is ever wrong, the
> sandbox forces an opaque origin and disables script execution so a
> misclassified file cannot run as a document in our origin. It does not
> interfere with inline viewing — \`sandbox\` sandboxes scripts \*inside\* the
> served file, not the browser's native rendering of it. Chrome's built-in PDF
> viewer and Firefox's pdf.js both render sandboxed PDFs identically to
> unsandboxed ones, and images/audio/video decode natively regardless.
> 
> A spec locks the allowlist invariant by asserting no inline-safe extension
> maps to a script-capable content type, so re-adding something like SVG or XML
> to the allowlist fails CI instead of becoming a stored XSS.

(cc @david)

ファイルをクリックすると自動的に別のタブで開くという点は、より #product の質問に該当します。

---

_[View the full topic](https://meta.discourse.org/t/regression-pdfs-download-initiated-on-click-should-be-open-in-new-tab/404910)._
