| title: Workflow HTML Origin (before) | |
| emoji: 🪟 | |
| colorFrom: gray | |
| colorTo: red | |
| sdk: gradio | |
| sdk_version: 6.23.1 | |
| python_version: '3.13' | |
| app_file: app.py | |
| pinned: false | |
| Minimal demo for an internal security audit finding (GR-AUD-02), fixed in [PR #13750](https://github.com/gradio-app/gradio/pull/13750). | |
| A one-node workflow generates an HTML page. The page prints the browser origin it is running in, and whether it can reach the app's `localStorage`. | |
| 1. press **Run** | |
| 2. on the *Generated page* node, press the open-in-new-tab button | |
| 3. read what the opened page reports | |
| **Running the latest released Gradio.** The page opens from a `blob:` URL, which inherits the app's origin, so it reports this Space's origin and `localStorage: reachable` — generated HTML running with the app's authority. Compare with [gradio-workflow-html-after](https://huggingface.co/spaces/abidlabs/gradio-workflow-html-after). | |