Repository navigation
Conversation
added 2 commits
August 15, 2026 21:08
`view-source:https://example.com` fetches what it names and shows the bytes instead of rendering them. No new URL parsing. `view-source:https://x` already parses as a URL whose scheme is `view-source` and whose path is the inner address, so `request_from_input` accepts it, the address bar shows it, and history holds it like any other entry. Opening it in a new tab is the existing `open_tab` command with that address; nothing here needs to know whether it is a new tab or the current one. The source is escaped and put in a `<pre>`, and that is the whole job. Nothing may reformat, pretty-print or re-serialise it: a source view that showed a parsed and re-emitted tree would be answering a different question. For a page whose claim is "there is no script here" it would be the wrong answer, because the reader is checking the bytes rather than the tree. The test pins the properties that matter: the script tag survives with its type readable, markup is escaped rather than interpolated, and ampersands are escaped before angle brackets -- the other order turns `<` into `&lt;` and quietly corrupts every escape on the page.
The scheme existed and the only way to reach it was to type it. Cmd-U is what Chrome and Safari bind, and it opens a new tab rather than replacing the page, so the source and the page it came from stay side by side. Inert on a tab that is already showing source: the naive version opens view-source:view-source:https://..., which the address bar accepts and nothing can render.
Owner
Author
|
Folded into #19, which now carries this whole stack against master. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #17.
view-source:https://example.comfetches what it names and shows the bytesinstead of rendering them.
No new URL parsing
view-source:https://xalready parses as a URL whose scheme isview-sourceand whose path is the inner address. So
request_from_inputaccepts itunchanged, the address bar shows it, and history holds it like any other entry.
Opening it in a new tab is the existing
open_tabcommand with thataddress — nothing here needs to know whether it landed in a new tab or the
current one, which is why no new plumbing was needed for that.
Escaped into a
<pre>, and nothing elseNothing may reformat, pretty-print or re-serialise. A source view that showed a
parsed and re-emitted tree would be answering a different question, and for a
page whose claim is there is no script here it would be the wrong answer: the
reader is checking the bytes, not the tree.
The test pins three properties:
typereadable<into&lt;and quietly corrupts every escape on the pageVerified
Ran against the live site in the window:
chuzz-gui "view-source:https://vliw-12345.xyz/"fetches and renders with noerror, window healthy at 197 MB RSS.
25 tests, clippy clean, fmt clean.
--capturecannot verify this, the same gap #17 notes: it loads throughdocument_loader, which fetches directly, soview-source:reaches reqwest asa bad scheme. Both that and the wasm-tag path would be covered by teaching the
capture loader the same routing.