Outcome
Bound browser memory use for large Source File downloads or provide an explicit safe browser-side limit and fallback.
Current behavior
Core can expose Source Files up to 512 MiB. The current Client materializes the response into a complete Uint8Array, and Web then creates a Blob, which can cause a large transient memory peak even though small-file lifecycle behavior is correct.
Acceptance criteria
- Choose and document a browser-safe strategy: streaming to an approved sink where available, or an explicit lower Web download threshold with a clear fallback.
- Keep response status, content length, content type, and filename validation fail-closed.
- Never place bearer credentials in a URL, browser history, or persistent storage.
- Do not auto-retry an interrupted download.
- Add focused tests for the selected threshold/streaming behavior and cleanup after success, cancellation, and failure.
Non-goals
- Changing Core's Source File size contract.
- Persisting execution-principal credentials in the browser.
- Treating a partial download as success.
Outcome
Bound browser memory use for large Source File downloads or provide an explicit safe browser-side limit and fallback.
Current behavior
Core can expose Source Files up to 512 MiB. The current Client materializes the response into a complete
Uint8Array, and Web then creates a Blob, which can cause a large transient memory peak even though small-file lifecycle behavior is correct.Acceptance criteria
Non-goals