Tutorials

Claude Opus 5.5: fix product downloads that open a new page

When a product PDF or campaign image opens instead of downloading, ask Claude Opus 5.5 to trace the link's final origin and response headers.

Fictional product · ad example

Make it with Panelly

Turn inspiration into your next product ad

Bring a product image and an idea. Create a four-panel ad, a coordinated asset set, or a video with Panelly.

Create with Panelly Edit the brief before you generate.
AI editorial concept: blue bottle prints connected by terracotta thread beneath a brass loupe.

When a product PDF or campaign image opens instead of downloading, ask Claude Opus 5.5 to trace the link's final origin and response headers. Adding download to an anchor does not control an arbitrary external server. Separate ordinary navigation, server-directed attachment delivery and a permitted fetch-to-Blob flow before choosing a repair.

Choose the delivery mechanism

SituationInspectCandidate approach
File shares the page's originAnchor and response dispositionA normal download link, verified in target browsers
File is on a controlled asset hostFinal response headersServe it as an attachment with an appropriate filename
JavaScript needs to read an external fileCORS permission, size and authorizationFetch to a Blob only when permitted and justified

MDN's anchor reference limits the download attribute to same-origin URLs and blob: or data: schemes. Its Content-Disposition reference explains attachment handling. CORS permission to read a response and a server's download disposition answer different questions; adding a permissive CORS header is not a general repair for an external anchor.

Compare origins, not familiar-looking names

In a hypothetical site at https://shop.example, /files/spec.pdf has the same origin. https://assets.shop.example/spec.pdf does not, despite sharing a parent domain. https://shop.example:8443/spec.pdf also differs because the port changes. https://shop.example:443/spec.pdf normalizes to the same HTTPS origin. These four URL comparisons were computed locally; no remote download was executed.

Record the full redirect chain. A same-origin-looking link can end at another host, an expired signed link can return an error document, and a 200 response can still contain HTML rather than the intended PDF. Keep signed query parameters out of shared reports. Inspect the final status, content type, disposition and expected file identity instead of calling any saved file a successful download.

A bounded repair prompt

Review this product download using the anchor markup, page origin, sanitized redirect chain and final response headers. Classify navigation, attachment delivery and fetch-to-Blob separately. Compare https://shop.example with /files/spec.pdf, https://assets.shop.example/spec.pdf, https://shop.example:8443/spec.pdf and https://shop.example:443/spec.pdf. Explain origin differences. Propose the smallest repair using only hosts we control and permissions already granted. Preserve access checks, signed-link expiry, TLS and the user's explicit click. Do not add an unrestricted proxy or disable browser protections. Return required headers, filename behavior, loading/error states and tests for a real PDF, expired link and unauthorized response. Verify file content as well as its extension. Mark tests not run and redact private query tokens.

The official Opus guide is the model reference; this is a proposed review, not a model or browser-download test. A 2015 community question records the same CORS-versus-download confusion. Its historical browser details are not used as current compatibility facts.

Validate the saved artifact

For a server you control, a candidate response is Content-Disposition: attachment; filename="product-spec.pdf", with the correct content type and authorized content. Test the final response after redirects. For international filenames, validate your server's supported filename encoding and actual browser behavior rather than concatenating untrusted names into headers.

A Blob flow may require holding substantial data in memory and must handle failed fetches, cancellation and object-URL cleanup. Do not introduce it merely to rename a large file. Show completion only after the application's actual observable step; opening a tab or receiving headers does not prove the user saved an intact artifact. Keep the fallback link understandable when automatic behavior differs by browser settings.

For naming collisions after successful delivery, use the Unicode filename guide. Create the campaign artwork in Panelly Studio, then test your own delivery path with a real saved asset. This does not claim that Panelly integrates Opus or that its download implementation was tested here.

Download questions

Does the same parent domain mean the same origin?

No. Scheme, host and effective port determine the origin. A subdomain can change it.

Does an attachment header override every user preference?

No. Browsers and user settings influence handling. Verify the intended clients and provide a usable fallback.

Can a public proxy solve it?

Do not send protected or signed assets to an arbitrary proxy. Repair a controlled delivery endpoint while retaining authorization and expiration rules.

Sources and further reading

Four panels. One ad.

Your next ad starts here.

Describe your product, its benefits and its audience. Create a four-panel ad with Panelly.

Start creating ↗View credit packs