ExperimentExperimental

Experiment: IDOP documents as viewers

Opening a .docx or an HTML file with an IDOP document as its viewer — which receives exactly that file and nothing else.

IDOP LABS1 min read

Secure executionFile formats

A reader that runs interactive documents can also use them to display other files. Instead of building a renderer for every format into the reader, a small IDOP document can be the viewer: the user opens a .docx, and the reader hands that one file to a viewer document through idop.host.getInputFile().

The constraint that makes it safe

The viewer runs in the same sandbox as any other document. It receives the bytes of the file the user chose — and nothing else from their storage. It has no network unless it declares one and the user allows it. If it edits the file, it hands a copy back with idop.host.putOutputFile(), which writes nothing by itself; the reader asks the user what to do with it.

What exists

IDOP Cloud ships two first-party viewers as templates, for .docx and for HTML. The HTML viewer exists because showing arbitrary HTML inside the reader’s own page would be unsafe: inside a viewer document it is shown in a fixed-height frame, with no network and nothing to escape to.

Open questions

How a user chooses default viewers, how third-party viewers earn trust, and how a viewer declares the formats it handles are still open. The specification describes viewers only informatively (§11.4).