Repro: GIFOCUS fetch() CSV Export Failure in Menlo Isolation

Why your previous test did not reproduce the issue:
In your initial test, the page ran in a standard browser session where gifocus_create_csv.php returned the actual CSV with Content-Disposition: attachment.
Because Content-Disposition was present, the script took the if (disposition) branch, constructed an in-memory Blob, and triggered an anchor download (a.click()). In Menlo, clicking a blob download link automatically opens a new tab and scans the file normally without errors.

What happened in customer's production (Fujitsu TID 3991):
The customer connects through Menlo Squid Proxy with ICAP File Download Inspection. When the backend responded to fetch() with a CSV file, Menlo Proxy intercepted the response and substituted it with Menlo's HTML download page (Content-Type: text/html, NO Content-Disposition header).
Because Content-Disposition was null, GIFOCUS executed its fallback error branch:
const doc = new DOMParser().parseFromString(await res.text(), 'text/html');
document.body.innerHTML = doc.body.innerHTML; // Strips Menlo's <head> CSS & JS!

Bilingual Translation Glossary (Japanese → English)

Here is what all Japanese terms in the customer's portal and error screens mean:

Japanese Text (Customer View) English Translation Context
CSV出力 (絞り込み) CSV Export (Filter) Screen title of mg03d01 dialog
指定された条件によりユーザデータよりCSVファイルの出力を行います。 Exports CSV file from user data based on specified conditions. Dialog description
対象ユーザデータ Target User Data Form dropdown (e.g. IT-116)
検索項目 Search Filter Item Filter criteria input fields
ファイルダウンロード中 File download in progress / Contacting server Menlo status #loading (should be hidden)
ドキュメントを読み込んでいます... Loading document... Menlo status #transfer (should be hidden)
エラーが発生しました
以下のファイル処理中に問題が発生しました:
ファイル名 : IT-116_...csv
リトライしてください。
An error occurred
A problem occurred while processing the following file:
File Name: IT-116_...csv
Please retry.
Menlo block-error #block-error. Not a real error! Renders only because Menlo's .hidden { display: none } CSS was lost!
コンテンツのスキャンが完了しました Content scan completed (Clean) Menlo SafeDocs status inside the viewer iframe
ファイルダウンロードでiframeの使用が要求されています。 An iframe is required for file download. Fallback text inside #download_monitor iframe

How to Test with the Buttons in the Dialog Below

  1. Flow 1: Test Baseline Normal Download (if (disposition) Branch via Blob)
    • Click ✔ Flow 1: CSV Export (Normal Origin CSV via Blob).
    • gifocus_create_csv.php returns the real CSV with Content-Disposition: attachment.
    • The client JS detects Content-Disposition, takes the if (disposition) branch, and downloads the file via in-memory Blob without modifying the page UI.
    • The on-screen diagnostics box shows green: ✔ if (disposition) → Normal Blob Download Branch.
  2. Flow 2: Test Menlo ICAP Interception & Template (Buggy else Branch)
    • Click ⚡ Flow 2: CSV Export with Menlo ICAP Interception (Buggy else Branch).
    • gifocus_create_csv.php dynamically loads the real template from /home/vagrant/git/menlo-icap/templates/file-download-frame.html on disk (zero hardcoded HTML) and omits Content-Disposition.
    • The client JS detects Content-Disposition is NULL and takes the else fallback branch (document.body.innerHTML = doc.body.innerHTML).
    • Before Fix: Because <head> was discarded, file-download.css is missing: "エラーが発生しました" falsely displays, and the iframe collapses to 300×150 px!
    • After Fix: When file-download-frame.html has inline protection styles, no false error displays, and the iframe opens cleanly as a full-screen modal!
  3. Case 3: Clean CSV Export & Response Inspector (Normal without Menlo ICAP / No Templates)
    • Click 📄 Case 3: Clean CSV Export & Inspector (Normal No-ICAP Format).
    • No templates used: Does not use file-download-frame.html or any mock HTML frame.
    • Demonstrates how the request processes in standard format without Menlo ICAP:
      • Sends standard POST request with filter criteria.
      • Receives genuine text/csv; charset=UTF-8 stream with Content-Disposition: attachment; filename="IT-116_....csv".
      • Parses and displays an immediate CSV Data Preview Table with records and headers.
      • Renders full HTTP metadata (Content-Type, Content-Disposition, file size).
      • Downloads the clean CSV file directly without touching or corrupting the DOM.
  4. Direct Browser GET Download:
    • Click ⭳ Direct Browser GET Download to test traditional browser attachment download without JavaScript fetch().

GIFOCUS Export Dialog Frame (mg03d01 inside md01d01)