Class ApiRootAction.ViewEndpoint
- Enclosing class:
ApiRootAction
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionorg.kohsuke.stapler.HttpResponsedoComments(org.kohsuke.stapler.StaplerRequest2 req) POST /views/{id}/comments — add an inline or general comment, optionally as a threaded reply (parentId) and/or with a display-only author label (authorLabel, or setautomated:trueto use the configured global label).org.kohsuke.stapler.HttpResponsedoDecision(org.kohsuke.stapler.StaplerRequest2 req) POST /views/{id}/decision — record approve / reject / acknowledge (resolves a waiting step).org.kohsuke.stapler.HttpResponseGET /views/{id}/download — the current version's content as a file attachment.org.kohsuke.stapler.HttpResponseGET /views/{id}/downloadGroup — every readable document published together with this one (samegroupIdon the same build) as a single ZIP; a lone document yields a one-entry archive.org.kohsuke.stapler.HttpResponsedoEdit(org.kohsuke.stapler.StaplerRequest2 req) POST /views/{id}/edit — save an edit to the durable review copy as a new version.org.kohsuke.stapler.HttpResponsedoIndex()GET /views/{id} — detail (metadata + comments + current content).org.kohsuke.stapler.HttpResponsedoRaw(org.kohsuke.stapler.StaplerRequest2 req) GET /views/{id}/raw?version=n — one content version as JSON{version, content}.org.kohsuke.stapler.HttpResponsedoRendered(org.kohsuke.stapler.StaplerRequest2 req) GET /views/{id}/rendered?version=n — the snapshot astext/htmlfor display inside the review page's sandboxed frame ("Rendered" view), so a generated report is readable as a report rather than as escaped source.org.kohsuke.stapler.HttpResponsedoResolveComment(org.kohsuke.stapler.StaplerRequest2 req) POST /views/{id}/resolveComment — toggle a comment's resolved flag.
-
Constructor Details
-
ViewEndpoint
-
-
Method Details
-
doIndex
@GET public org.kohsuke.stapler.HttpResponse doIndex()GET /views/{id} — detail (metadata + comments + current content). 404 if not readable. -
doRaw
@GET public org.kohsuke.stapler.HttpResponse doRaw(org.kohsuke.stapler.StaplerRequest2 req) GET /views/{id}/raw?version=n — one content version as JSON{version, content}. -
doRendered
@GET public org.kohsuke.stapler.HttpResponse doRendered(org.kohsuke.stapler.StaplerRequest2 req) GET /views/{id}/rendered?version=n — the snapshot astext/htmlfor display inside the review page's sandboxed frame ("Rendered" view), so a generated report is readable as a report rather than as escaped source.Read-only (no CSRF needed) and permission-checked exactly like
doRaw(org.kohsuke.stapler.StaplerRequest2):Item.READviaViewStore.canView(io.jenkins.plugins.interactiveinput.view.ReviewDocument), else 404 (no existence leak). Two further gates keep this from becoming a general "serve arbitrary HTML from Jenkins" endpoint: it 404s unless thehtmlRenderingfeature is on, and unless the document really is an HTML snapshot (ApiRootAction.htmlRenderable(io.jenkins.plugins.interactiveinput.view.ReviewDocument)) — a markdown or code document is never served this way.The bytes are untrusted, so the isolation lives entirely in the response headers — see
SandboxedHtmlResponse, which serves them underContent-Security-Policy: sandbox allow-scripts(an opaque origin that cannot touch this Jenkins session, even if the URL is opened directly). -
doDownload
@GET public org.kohsuke.stapler.HttpResponse doDownload()GET /views/{id}/download — the current version's content as a file attachment.Read-only (no CSRF needed) and permission-checked exactly like
doIndex():Item.READviaViewStore.canView(io.jenkins.plugins.interactiveinput.view.ReviewDocument), else 404 (no existence leak). The download name is the snapshot's basename, further sanitised byDownloadHttpResponse. -
doDownloadGroup
@GET public org.kohsuke.stapler.HttpResponse doDownloadGroup()GET /views/{id}/downloadGroup — every readable document published together with this one (samegroupIdon the same build) as a single ZIP; a lone document yields a one-entry archive.Read-only and permission-checked like
doDownload(): the anchor document must be readable (Item.READ, else 404), and only co-group members the caller can also read are included (ViewStore.listForBuild(java.lang.String, int)already appliescanView). ZIP entry names are sanitised (no CR/LF, no leading/, no./..segments) and de-duplicated. -
doComments
public org.kohsuke.stapler.HttpResponse doComments(org.kohsuke.stapler.StaplerRequest2 req) POST /views/{id}/comments — add an inline or general comment, optionally as a threaded reply (parentId) and/or with a display-only author label (authorLabel, or setautomated:trueto use the configured global label). The audit author is always the authenticated Jenkins identity — never taken from the request — so a label cannot spoof it. -
doEdit
public org.kohsuke.stapler.HttpResponse doEdit(org.kohsuke.stapler.StaplerRequest2 req) POST /views/{id}/edit — save an edit to the durable review copy as a new version. -
doDecision
public org.kohsuke.stapler.HttpResponse doDecision(org.kohsuke.stapler.StaplerRequest2 req) POST /views/{id}/decision — record approve / reject / acknowledge (resolves a waiting step). -
doResolveComment
public org.kohsuke.stapler.HttpResponse doResolveComment(org.kohsuke.stapler.StaplerRequest2 req) POST /views/{id}/resolveComment — toggle a comment's resolved flag.
-