I hope we can turn off the "unsafe download" thing. I download files every day that I know are perfectly safe, precisely because the file will only ever be downloaded once, by me, because I just built it in Gitlab.
The second part of this feature is that for <iframe sandbox="..."> elements, regardless of HTTP/S origin, Firefox will no longer allow the iframe to initiate downloads unless the sandbox attribute explicitly includes allow-downloads
It appears that there are a pair of preferences in about:config to govern these: dom.block_download_insecure and dom.block_download_in_sandboxed_iframes