Tutorials
Claude Opus 5.5: fix product downloads that open a new page
When a product PDF or campaign image opens instead of downloading, ask Claude Opus 5.5 to trace the link's final origin and response headers.

Make it with Panelly
Turn inspiration into your next product ad
Bring a product image and an idea. Create a four-panel ad, a coordinated asset set, or a video with Panelly.
Create with Panelly Edit the brief before you generate.
When a product PDF or campaign image opens instead of downloading, ask Claude Opus 5.5 to trace the link's final origin and response headers. Adding download to an anchor does not control an arbitrary external server. Separate ordinary navigation, server-directed attachment delivery and a permitted fetch-to-Blob flow before choosing a repair.
Choose the delivery mechanism
| Situation | Inspect | Candidate approach |
|---|---|---|
| File shares the page's origin | Anchor and response disposition | A normal download link, verified in target browsers |
| File is on a controlled asset host | Final response headers | Serve it as an attachment with an appropriate filename |
| JavaScript needs to read an external file | CORS permission, size and authorization | Fetch to a Blob only when permitted and justified |
MDN's anchor reference limits the download attribute to same-origin URLs and blob: or data: schemes. Its Content-Disposition reference explains attachment handling. CORS permission to read a response and a server's download disposition answer different questions; adding a permissive CORS header is not a general repair for an external anchor.
Compare origins, not familiar-looking names
In a hypothetical site at https://shop.example, /files/spec.pdf has the same origin. https://assets.shop.example/spec.pdf does not, despite sharing a parent domain. https://shop.example:8443/spec.pdf also differs because the port changes. https://shop.example:443/spec.pdf normalizes to the same HTTPS origin. These four URL comparisons were computed locally; no remote download was executed.
Record the full redirect chain. A same-origin-looking link can end at another host, an expired signed link can return an error document, and a 200 response can still contain HTML rather than the intended PDF. Keep signed query parameters out of shared reports. Inspect the final status, content type, disposition and expected file identity instead of calling any saved file a successful download.
A bounded repair prompt
Review this product download using the anchor markup, page origin, sanitized redirect chain and final response headers. Classify navigation, attachment delivery and fetch-to-Blob separately. Compare https://shop.example with /files/spec.pdf, https://assets.shop.example/spec.pdf, https://shop.example:8443/spec.pdf and https://shop.example:443/spec.pdf. Explain origin differences. Propose the smallest repair using only hosts we control and permissions already granted. Preserve access checks, signed-link expiry, TLS and the user's explicit click. Do not add an unrestricted proxy or disable browser protections. Return required headers, filename behavior, loading/error states and tests for a real PDF, expired link and unauthorized response. Verify file content as well as its extension. Mark tests not run and redact private query tokens.
The official Opus guide is the model reference; this is a proposed review, not a model or browser-download test. A 2015 community question records the same CORS-versus-download confusion. Its historical browser details are not used as current compatibility facts.
Validate the saved artifact
For a server you control, a candidate response is Content-Disposition: attachment; filename="product-spec.pdf", with the correct content type and authorized content. Test the final response after redirects. For international filenames, validate your server's supported filename encoding and actual browser behavior rather than concatenating untrusted names into headers.
A Blob flow may require holding substantial data in memory and must handle failed fetches, cancellation and object-URL cleanup. Do not introduce it merely to rename a large file. Show completion only after the application's actual observable step; opening a tab or receiving headers does not prove the user saved an intact artifact. Keep the fallback link understandable when automatic behavior differs by browser settings.
For naming collisions after successful delivery, use the Unicode filename guide. Create the campaign artwork in Panelly Studio, then test your own delivery path with a real saved asset. This does not claim that Panelly integrates Opus or that its download implementation was tested here.
Download questions
Does the same parent domain mean the same origin?
No. Scheme, host and effective port determine the origin. A subdomain can change it.
Does an attachment header override every user preference?
No. Browsers and user settings influence handling. Verify the intended clients and provide a usable fallback.
Can a public proxy solve it?
Do not send protected or signed assets to an arbitrary proxy. Repair a controlled delivery endpoint while retaining authorization and expiration rules.


