
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@file-viewer/renderer-word
Advanced tools
Standalone DOCX, DOC, and OpenDocument renderer for File Viewer; RTF parsing is an explicit opt-in capability.
Flyfish File Viewer 的 Word / OpenDocument renderer 包。standard/full 默认承接 DOCX/DOCM/DOTX/DOTM、旧版 DOC/DOT 与 ODT/ODP;RTF 由 @file-viewer/capability-rtf 显式启用。
import FileViewer from '@file-viewer/vue3'
import { wordRenderer } from '@file-viewer/renderer-word'
const options = {
rendererMode: 'replace',
renderers: wordRenderer,
}
也可以和其他 renderer 一起组合:
import { wordRenderer } from '@file-viewer/renderer-word'
import { pdfRenderer } from '@file-viewer/renderer-pdf'
import { presentationRenderer } from '@file-viewer/renderer-presentation'
const options = {
rendererMode: 'replace',
renderers: [wordRenderer, pdfRenderer, presentationRenderer],
}
官方 Demo 和完整格式矩阵可以直接使用 @file-viewer/preset-all。
@file-viewer/docx,默认 Worker 解析、连续流式阅读、目录字段缓存、异步分批渲染,并跟随 viewer 主题启用暗黑文档面。@file-viewer/doc,并套用 Word 风格纸张阅读面、缩放、打印和 HTML 导出适配。rtf.js;未安装时会显示精确 CLI 启用命令。ODT / ODP 读取 OpenDocument 包内 content.xml 做安全结构预览。options.docx.reviewMode 同时适用于 DOC 和 DOCX:all(默认)用下划线显示实际插入、用删除线显示实际删除;final 显示定稿,original 显示修订前文字。同一组件修改该参数后会更新预览,不需要重新选择文件,也不会接受、拒绝修订或重写原始文件。文本修订支持不等于完整支持 Word 审阅历史、格式修订或移动记录。
DOCX Worker 默认读取 viewer assets 下的:
vendor/docx/docx.worker.jsvendor/docx/jszip.min.js私有化部署时可以通过 options.docx.workerUrl 和 options.docx.workerJsZipUrl 覆盖:
const options = {
docx: {
workerUrl: '/file-viewer/vendor/docx/docx.worker.js',
workerJsZipUrl: '/file-viewer/vendor/docx/jszip.min.js',
},
}
DOCX 暗黑渲染默认由 options.theme 决定:dark 开启、light 关闭、system 跟随浏览器系统主题。需要业务固定效果时可传 options.docx.darkMode: true / false。
DOC、DOCX 与 RTF 的外部链接及 HTTP(S) 图片关系默认阻断。只有显式设置 options.docx.externalLinkPolicy: 'allow' 和 options.docx.externalResourcePolicy: 'allow' 才会启用;链接仍只接受 HTTP(S)、mailto:、tel: 和安全相对地址,未知协议与协议相对地址始终拒绝。内嵌图片、内部书签以及本地 data:/blob: 图片资源不受影响。
标准 renderer 会在挂载前净化 rtf.js 产生的 DOM。自定义 RTF 集成若直接消费 HTML,应先调用 sanitizeFileViewerRtfHtml(document, markup, options);该边界与标准挂载使用同一链接策略和 DOMPurify 配置。严格 Trusted Types CSP 需允许 file-viewer-document-sanitizer 策略名。
@file-viewer/core 已不再直接依赖 @file-viewer/docx、@file-viewer/doc、rtf.js、linkedom 或 @xmldom/xmldom。需要 Word 完整预览时,请安装本包并通过 renderers 传入,或使用 @file-viewer/preset-all。
FAQs
Standalone DOCX, DOC, and OpenDocument renderer for File Viewer; RTF parsing is an explicit opt-in capability.
The npm package @file-viewer/renderer-word receives a total of 14,763 weekly downloads. As such, @file-viewer/renderer-word popularity was classified as popular.
We found that @file-viewer/renderer-word demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.