feat: Add customization URL parameter (#5992)
* Add customization URL parameter
* fix: Preserve should be customizeable
* Update customizations docs
* fix: Overlay items on patient name
* Add customization test
* Fix resolve to absolute path
* fix: Warn on no data in load
* Remove unused customization stuff
* fix: PR comments
* Update stored parameters to only use an array for mulitples
* Remove requires ohif.* special call out
* Remove strict mode
* PR comments
* Document segmentation examples
* Add three examples as requested
* PR comments
* lock
* Remove old customizatoin export
* fix: Ordering issues on customization loads
* fix: Use correct default for dev builds app config
* Fixes for conflicts
* chore: restore pnpm-lock.yaml to match master
The lockfile diff was incidental peer-descriptor churn and carried no
functional dependency change. It tripped the CircleCI security-audit gate
(which only runs when pnpm-lock.yaml is in the PR diff), surfacing a
pre-existing critical `decompress` transitive vuln that also exists on
master. Restoring master's lockfile removes the audit trigger.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ci): restore json5 lockfile entry; ignore unfixable decompress GHSA
The previous commit restored pnpm-lock.yaml from master, which dropped the
json5@2.2.3 entry that platform/core legitimately depends on (JSONC parsing
for the customization feature). That broke `--frozen-lockfile` install
(ERR_PNPM_OUTDATED_LOCKFILE). This restores the correct lockfile.
Because the lockfile must change (json5), the CircleCI security-audit gate
runs and previously failed on a critical `decompress` <=4.2.1 zip-slip
advisory. This is a pre-existing transitive vuln (present on master too) with
no published patch — decompress's latest release is 4.2.1, so no version
bump/override can resolve it. It reaches the tree only via @itk-wasm/dam, a
build/data-asset extraction tool under @cornerstonejs/labelmap-interpolation.
Add GHSA-mp2f-45pm-3cg9 to the existing pnpm-workspace.yaml auditConfig
ignoreGhsas accepted-risk list, matching how the repo already exempts other
build-tooling advisories. `pnpm audit --audit-level high` now passes locally
(1 critical ignored, 0 high).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(e2e): fix visitStudy URL encoding that broke mpr2 study load
The visitStudy rewrite (added for the ?customization= option) built the URL
with new URLSearchParams({ StudyInstanceUIDs: studyInstanceUID }), which
percent-encodes the value. mpr2.spec.ts embeds an extra param in the UID
string ('<uid>&hangingprotocolid=mpr'), so the & and = were encoded and the
whole thing collapsed into one invalid StudyInstanceUIDs value -> the study
could not be found ('studies are not available'), the viewer never rendered,
and the side-panel-header-right click timed out.
Restore master's raw concatenation for StudyInstanceUIDs (so embedded params
survive as separate query params) while still appending the customization
option separately. Only mpr2 embeds & in the UID, matching the single failure.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* PR comments
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-07 21:30:27 +02:00
/** @type {AppTypes.Config} */
// Local development configuration.
//
// This is the default config for the dev server (`pnpm run dev`, `dev:fast`,
2026-07-10 18:43:17 +02:00
// `start`). It is intentionally kept at parity with config/netlify.js (the
// public demo deploy): every data source is enabled, the `?customization=` URL
// feature is ON via `customizationUrlPrefixes`, and the same startup
// `customizationService` modules are loaded — so the whole app, including
// customizations, can be exercised locally exactly as it runs on the demo.
// The locked-down config/default.js is what a plain production build emits
// instead.
feat: Add customization URL parameter (#5992)
* Add customization URL parameter
* fix: Preserve should be customizeable
* Update customizations docs
* fix: Overlay items on patient name
* Add customization test
* Fix resolve to absolute path
* fix: Warn on no data in load
* Remove unused customization stuff
* fix: PR comments
* Update stored parameters to only use an array for mulitples
* Remove requires ohif.* special call out
* Remove strict mode
* PR comments
* Document segmentation examples
* Add three examples as requested
* PR comments
* lock
* Remove old customizatoin export
* fix: Ordering issues on customization loads
* fix: Use correct default for dev builds app config
* Fixes for conflicts
* chore: restore pnpm-lock.yaml to match master
The lockfile diff was incidental peer-descriptor churn and carried no
functional dependency change. It tripped the CircleCI security-audit gate
(which only runs when pnpm-lock.yaml is in the PR diff), surfacing a
pre-existing critical `decompress` transitive vuln that also exists on
master. Restoring master's lockfile removes the audit trigger.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ci): restore json5 lockfile entry; ignore unfixable decompress GHSA
The previous commit restored pnpm-lock.yaml from master, which dropped the
json5@2.2.3 entry that platform/core legitimately depends on (JSONC parsing
for the customization feature). That broke `--frozen-lockfile` install
(ERR_PNPM_OUTDATED_LOCKFILE). This restores the correct lockfile.
Because the lockfile must change (json5), the CircleCI security-audit gate
runs and previously failed on a critical `decompress` <=4.2.1 zip-slip
advisory. This is a pre-existing transitive vuln (present on master too) with
no published patch — decompress's latest release is 4.2.1, so no version
bump/override can resolve it. It reaches the tree only via @itk-wasm/dam, a
build/data-asset extraction tool under @cornerstonejs/labelmap-interpolation.
Add GHSA-mp2f-45pm-3cg9 to the existing pnpm-workspace.yaml auditConfig
ignoreGhsas accepted-risk list, matching how the repo already exempts other
build-tooling advisories. `pnpm audit --audit-level high` now passes locally
(1 critical ignored, 0 high).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(e2e): fix visitStudy URL encoding that broke mpr2 study load
The visitStudy rewrite (added for the ?customization= option) built the URL
with new URLSearchParams({ StudyInstanceUIDs: studyInstanceUID }), which
percent-encodes the value. mpr2.spec.ts embeds an extra param in the UID
string ('<uid>&hangingprotocolid=mpr'), so the & and = were encoded and the
whole thing collapsed into one invalid StudyInstanceUIDs value -> the study
could not be found ('studies are not available'), the viewer never rendered,
and the side-panel-header-right click timed out.
Restore master's raw concatenation for StudyInstanceUIDs (so embedded params
survive as separate query params) while still appending the customization
option separately. Only mpr2 embeds & in the UID, matching the single failure.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* PR comments
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-07 21:30:27 +02:00
window . config = {
name : 'config/dev.js' ,
routerBasename : null ,
// whiteLabeling: {},
extensions : [ ] ,
modes : [ ] ,
2026-07-10 18:43:17 +02:00
customizationService : [ '@ohif/extension-default.customizationModule.theme' ] ,
feat: Add customization URL parameter (#5992)
* Add customization URL parameter
* fix: Preserve should be customizeable
* Update customizations docs
* fix: Overlay items on patient name
* Add customization test
* Fix resolve to absolute path
* fix: Warn on no data in load
* Remove unused customization stuff
* fix: PR comments
* Update stored parameters to only use an array for mulitples
* Remove requires ohif.* special call out
* Remove strict mode
* PR comments
* Document segmentation examples
* Add three examples as requested
* PR comments
* lock
* Remove old customizatoin export
* fix: Ordering issues on customization loads
* fix: Use correct default for dev builds app config
* Fixes for conflicts
* chore: restore pnpm-lock.yaml to match master
The lockfile diff was incidental peer-descriptor churn and carried no
functional dependency change. It tripped the CircleCI security-audit gate
(which only runs when pnpm-lock.yaml is in the PR diff), surfacing a
pre-existing critical `decompress` transitive vuln that also exists on
master. Restoring master's lockfile removes the audit trigger.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ci): restore json5 lockfile entry; ignore unfixable decompress GHSA
The previous commit restored pnpm-lock.yaml from master, which dropped the
json5@2.2.3 entry that platform/core legitimately depends on (JSONC parsing
for the customization feature). That broke `--frozen-lockfile` install
(ERR_PNPM_OUTDATED_LOCKFILE). This restores the correct lockfile.
Because the lockfile must change (json5), the CircleCI security-audit gate
runs and previously failed on a critical `decompress` <=4.2.1 zip-slip
advisory. This is a pre-existing transitive vuln (present on master too) with
no published patch — decompress's latest release is 4.2.1, so no version
bump/override can resolve it. It reaches the tree only via @itk-wasm/dam, a
build/data-asset extraction tool under @cornerstonejs/labelmap-interpolation.
Add GHSA-mp2f-45pm-3cg9 to the existing pnpm-workspace.yaml auditConfig
ignoreGhsas accepted-risk list, matching how the repo already exempts other
build-tooling advisories. `pnpm audit --audit-level high` now passes locally
(1 critical ignored, 0 high).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(e2e): fix visitStudy URL encoding that broke mpr2 study load
The visitStudy rewrite (added for the ?customization= option) built the URL
with new URLSearchParams({ StudyInstanceUIDs: studyInstanceUID }), which
percent-encodes the value. mpr2.spec.ts embeds an extra param in the UID
string ('<uid>&hangingprotocolid=mpr'), so the & and = were encoded and the
whole thing collapsed into one invalid StudyInstanceUIDs value -> the study
could not be found ('studies are not available'), the viewer never rendered,
and the side-panel-header-right click timed out.
Restore master's raw concatenation for StudyInstanceUIDs (so embedded params
survive as separate query params) while still appending the customization
option separately. Only mpr2 embeds & in the UID, matching the single failure.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* PR comments
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-07 21:30:27 +02:00
// URL-driven customizations (?customization=). The `default` prefix (no
// slashes) is used for values without a leading slash; every other prefix
// must start AND end with a slash and matches the leading `/segment/` of the
// value. Files are fetched and parsed as JSONC data — never executed.
2026-07-10 18:43:17 +02:00
// e.g. ?customization=tools/ctPresets -> ./customizations/tools/ctPresets.jsonc
feat: Add customization URL parameter (#5992)
* Add customization URL parameter
* fix: Preserve should be customizeable
* Update customizations docs
* fix: Overlay items on patient name
* Add customization test
* Fix resolve to absolute path
* fix: Warn on no data in load
* Remove unused customization stuff
* fix: PR comments
* Update stored parameters to only use an array for mulitples
* Remove requires ohif.* special call out
* Remove strict mode
* PR comments
* Document segmentation examples
* Add three examples as requested
* PR comments
* lock
* Remove old customizatoin export
* fix: Ordering issues on customization loads
* fix: Use correct default for dev builds app config
* Fixes for conflicts
* chore: restore pnpm-lock.yaml to match master
The lockfile diff was incidental peer-descriptor churn and carried no
functional dependency change. It tripped the CircleCI security-audit gate
(which only runs when pnpm-lock.yaml is in the PR diff), surfacing a
pre-existing critical `decompress` transitive vuln that also exists on
master. Restoring master's lockfile removes the audit trigger.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ci): restore json5 lockfile entry; ignore unfixable decompress GHSA
The previous commit restored pnpm-lock.yaml from master, which dropped the
json5@2.2.3 entry that platform/core legitimately depends on (JSONC parsing
for the customization feature). That broke `--frozen-lockfile` install
(ERR_PNPM_OUTDATED_LOCKFILE). This restores the correct lockfile.
Because the lockfile must change (json5), the CircleCI security-audit gate
runs and previously failed on a critical `decompress` <=4.2.1 zip-slip
advisory. This is a pre-existing transitive vuln (present on master too) with
no published patch — decompress's latest release is 4.2.1, so no version
bump/override can resolve it. It reaches the tree only via @itk-wasm/dam, a
build/data-asset extraction tool under @cornerstonejs/labelmap-interpolation.
Add GHSA-mp2f-45pm-3cg9 to the existing pnpm-workspace.yaml auditConfig
ignoreGhsas accepted-risk list, matching how the repo already exempts other
build-tooling advisories. `pnpm audit --audit-level high` now passes locally
(1 critical ignored, 0 high).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test(e2e): fix visitStudy URL encoding that broke mpr2 study load
The visitStudy rewrite (added for the ?customization= option) built the URL
with new URLSearchParams({ StudyInstanceUIDs: studyInstanceUID }), which
percent-encodes the value. mpr2.spec.ts embeds an extra param in the UID
string ('<uid>&hangingprotocolid=mpr'), so the & and = were encoded and the
whole thing collapsed into one invalid StudyInstanceUIDs value -> the study
could not be found ('studies are not available'), the viewer never rendered,
and the side-panel-header-right click timed out.
Restore master's raw concatenation for StudyInstanceUIDs (so embedded params
survive as separate query params) while still appending the customization
option separately. Only mpr2 embeds & in the UID, matching the single failure.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* PR comments
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-07 21:30:27 +02:00
customizationUrlPrefixes : {
default : './customizations/' ,
} ,
showStudyList : true ,
// some windows systems have issues with more than 3 web workers
maxNumberOfWebWorkers : 3 ,
// below flag is for performance reasons, but it might not work for all servers
showWarningMessageForCrossOrigin : true ,
showCPUFallbackMessage : true ,
showLoadingIndicator : true ,
experimentalStudyBrowserSort : false ,
strictZSpacingForVolumeViewport : true ,
groupEnabledModesFirst : true ,
allowMultiSelectExport : false ,
maxNumRequests : {
interaction : 100 ,
thumbnail : 5 ,
// Prefetch number is dependent on the http protocol. For http 2 or
// above, the number of requests can be go a lot higher.
prefetch : 25 ,
} ,
showErrorDetails : 'always' , // 'always', 'dev', 'production'
// filterQueryParam: false,
// Defines multi-monitor layouts
multimonitor : [
{
id : 'split' ,
test : ( { multimonitor } ) => multimonitor === 'split' ,
screens : [
{
id : 'ohif0' ,
screen : null ,
location : {
screen : 0 ,
width : 0.5 ,
height : 1 ,
left : 0 ,
top : 0 ,
} ,
options : 'location=no,menubar=no,scrollbars=no,status=no,titlebar=no' ,
} ,
{
id : 'ohif1' ,
screen : null ,
location : {
width : 0.5 ,
height : 1 ,
left : 0.5 ,
top : 0 ,
} ,
options : 'location=no,menubar=no,scrollbars=no,status=no,titlebar=no' ,
} ,
] ,
} ,
{
id : '2' ,
test : ( { multimonitor } ) => multimonitor === '2' ,
screens : [
{
id : 'ohif0' ,
screen : 0 ,
location : {
width : 1 ,
height : 1 ,
left : 0 ,
top : 0 ,
} ,
options : 'fullscreen=yes,location=no,menubar=no,scrollbars=no,status=no,titlebar=no' ,
} ,
{
id : 'ohif1' ,
screen : 1 ,
location : {
width : 1 ,
height : 1 ,
left : 0 ,
top : 0 ,
} ,
options : 'fullscreen=yes,location=no,menubar=no,scrollbars=no,status=no,titlebar=no' ,
} ,
] ,
} ,
] ,
defaultDataSourceName : 'ohif' ,
/* Dynamic config allows user to pass "configUrl" query string this allows to load config without recompiling application. The regex will ensure valid configuration source */
// dangerouslyUseDynamicConfig: {
// enabled: true,
// regex: /.*/,
// },
dataSources : [
{
namespace : '@ohif/extension-default.dataSourcesModule.dicomweb' ,
sourceName : 'ohif' ,
configuration : {
friendlyName : 'AWS S3 Static wado server' ,
name : 'aws' ,
wadoUriRoot : 'https://d14fa38qiwhyfd.cloudfront.net/dicomweb' ,
qidoRoot : 'https://d14fa38qiwhyfd.cloudfront.net/dicomweb' ,
wadoRoot : 'https://d14fa38qiwhyfd.cloudfront.net/dicomweb' ,
qidoSupportsIncludeField : false ,
imageRendering : 'wadors' ,
thumbnailRendering : 'thumbnail' ,
thumbnailRequestStrategy : 'fetch' ,
enableStudyLazyLoad : true ,
supportsFuzzyMatching : true ,
supportsWildcard : true ,
staticWado : true ,
singlepart : 'bulkdata,video' ,
bulkDataURI : {
enabled : true ,
relativeResolution : 'studies' ,
transform : url => url . replace ( '/pixeldata.mp4' , '/rendered' ) ,
} ,
omitQuotationForMultipartRequest : true ,
} ,
} ,
{
namespace : '@ohif/extension-default.dataSourcesModule.dicomweb' ,
sourceName : 'ohif2' ,
configuration : {
friendlyName : 'AWS S3 Static wado secondary server' ,
name : 'aws' ,
wadoUriRoot : 'https://dd14fa38qiwhyfd.cloudfront.net/dicomweb' ,
qidoRoot : 'https://dd14fa38qiwhyfd.cloudfront.net/dicomweb' ,
wadoRoot : 'https://dd14fa38qiwhyfd.cloudfront.net/dicomweb' ,
qidoSupportsIncludeField : false ,
supportsReject : false ,
imageRendering : 'wadors' ,
thumbnailRendering : 'wadors' ,
enableStudyLazyLoad : true ,
supportsFuzzyMatching : false ,
supportsWildcard : true ,
staticWado : true ,
singlepart : 'bulkdata,video' ,
bulkDataURI : {
enabled : true ,
relativeResolution : 'studies' ,
} ,
omitQuotationForMultipartRequest : true ,
} ,
} ,
{
namespace : '@ohif/extension-default.dataSourcesModule.dicomweb' ,
sourceName : 'ohif3' ,
configuration : {
friendlyName : 'AWS S3 Static wado secondary server' ,
name : 'aws' ,
wadoUriRoot : 'https://d3t6nz73ql33tx.cloudfront.net/dicomweb' ,
qidoRoot : 'https://d3t6nz73ql33tx.cloudfront.net/dicomweb' ,
wadoRoot : 'https://d3t6nz73ql33tx.cloudfront.net/dicomweb' ,
qidoSupportsIncludeField : false ,
supportsReject : false ,
imageRendering : 'wadors' ,
thumbnailRendering : 'wadors' ,
enableStudyLazyLoad : true ,
supportsFuzzyMatching : false ,
supportsWildcard : true ,
staticWado : true ,
singlepart : 'bulkdata,video' ,
bulkDataURI : {
enabled : true ,
relativeResolution : 'studies' ,
} ,
omitQuotationForMultipartRequest : true ,
} ,
} ,
{
namespace : '@ohif/extension-default.dataSourcesModule.dicomweb' ,
sourceName : 'local5000' ,
configuration : {
friendlyName : 'Static WADO Local Data' ,
name : 'DCM4CHEE' ,
qidoRoot : 'http://localhost:5000/dicomweb' ,
wadoRoot : 'http://localhost:5000/dicomweb' ,
qidoSupportsIncludeField : false ,
supportsReject : true ,
supportsStow : true ,
imageRendering : 'wadors' ,
thumbnailRendering : 'wadors' ,
enableStudyLazyLoad : true ,
supportsFuzzyMatching : false ,
supportsWildcard : true ,
staticWado : true ,
singlepart : 'video' ,
bulkDataURI : {
enabled : true ,
relativeResolution : 'studies' ,
} ,
} ,
} ,
{
namespace : '@ohif/extension-default.dataSourcesModule.dicomweb' ,
sourceName : 'orthanc' ,
configuration : {
friendlyName : 'local Orthanc DICOMWeb Server' ,
name : 'DCM4CHEE' ,
wadoUriRoot : 'http://localhost/pacs/dicom-web' ,
qidoRoot : 'http://localhost/pacs/dicom-web' ,
wadoRoot : 'http://localhost/pacs/dicom-web' ,
qidoSupportsIncludeField : true ,
supportsReject : true ,
dicomUploadEnabled : true ,
imageRendering : 'wadors' ,
thumbnailRendering : 'wadors' ,
enableStudyLazyLoad : true ,
supportsFuzzyMatching : true ,
supportsWildcard : true ,
omitQuotationForMultipartRequest : true ,
bulkDataURI : {
enabled : true ,
} ,
} ,
} ,
{
namespace : '@ohif/extension-default.dataSourcesModule.dicomwebproxy' ,
sourceName : 'dicomwebproxy' ,
configuration : {
friendlyName : 'dicomweb delegating proxy' ,
name : 'dicomwebproxy' ,
} ,
} ,
{
namespace : '@ohif/extension-default.dataSourcesModule.dicomjson' ,
sourceName : 'dicomjson' ,
configuration : {
friendlyName : 'dicom json' ,
name : 'json' ,
} ,
} ,
{
namespace : '@ohif/extension-default.dataSourcesModule.dicomlocal' ,
sourceName : 'dicomlocal' ,
configuration : {
friendlyName : 'dicom local' ,
} ,
} ,
] ,
httpErrorHandler : error => {
// This is 429 when rejected from the public idc sandbox too often.
console . warn ( error . status ) ;
// Could use services manager here to bring up a dialog/modal if needed.
console . warn ( 'test, navigate to https://ohif.org/' ) ;
} ,
} ;