Class ApiRootAction.ViewEndpoint

java.lang.Object
io.jenkins.plugins.interactiveinput.rest.ApiRootAction.ViewEndpoint
Enclosing class:
ApiRootAction

public static class ApiRootAction.ViewEndpoint extends Object
  • Constructor Summary

    Constructors
    Constructor
    Description
     
  • Method Summary

    Modifier and Type
    Method
    Description
    org.kohsuke.stapler.HttpResponse
    doComments(org.kohsuke.stapler.StaplerRequest2 req)
    POST /views/{id}/comments — add an inline or general comment, optionally as a threaded reply (parentId) and/or with a display-only author label (authorLabel, or set automated:true to use the configured global label).
    org.kohsuke.stapler.HttpResponse
    doDecision(org.kohsuke.stapler.StaplerRequest2 req)
    POST /views/{id}/decision — record approve / reject / acknowledge (resolves a waiting step).
    org.kohsuke.stapler.HttpResponse
    GET /views/{id}/download — the current version's content as a file attachment.
    org.kohsuke.stapler.HttpResponse
    GET /views/{id}/downloadGroup — every readable document published together with this one (same groupId on the same build) as a single ZIP; a lone document yields a one-entry archive.
    org.kohsuke.stapler.HttpResponse
    doEdit(org.kohsuke.stapler.StaplerRequest2 req)
    POST /views/{id}/edit — save an edit to the durable review copy as a new version.
    org.kohsuke.stapler.HttpResponse
    GET /views/{id} — detail (metadata + comments + current content).
    org.kohsuke.stapler.HttpResponse
    doRaw(org.kohsuke.stapler.StaplerRequest2 req)
    GET /views/{id}/raw?version=n — one content version as JSON {version, content}.
    org.kohsuke.stapler.HttpResponse
    doRendered(org.kohsuke.stapler.StaplerRequest2 req)
    GET /views/{id}/rendered?version=n — the snapshot as text/html for display inside the review page's sandboxed frame ("Rendered" view), so a generated report is readable as a report rather than as escaped source.
    org.kohsuke.stapler.HttpResponse
    doResolveComment(org.kohsuke.stapler.StaplerRequest2 req)
    POST /views/{id}/resolveComment — toggle a comment's resolved flag.

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Constructor Details

    • ViewEndpoint

      public ViewEndpoint(String id)
  • Method Details

    • doIndex

      @GET public org.kohsuke.stapler.HttpResponse doIndex()
      GET /views/{id} — detail (metadata + comments + current content). 404 if not readable.
    • doRaw

      @GET public org.kohsuke.stapler.HttpResponse doRaw(org.kohsuke.stapler.StaplerRequest2 req)
      GET /views/{id}/raw?version=n — one content version as JSON {version, content}.
    • doRendered

      @GET public org.kohsuke.stapler.HttpResponse doRendered(org.kohsuke.stapler.StaplerRequest2 req)
      GET /views/{id}/rendered?version=n — the snapshot as text/html for display inside the review page's sandboxed frame ("Rendered" view), so a generated report is readable as a report rather than as escaped source.

      Read-only (no CSRF needed) and permission-checked exactly like doRaw(org.kohsuke.stapler.StaplerRequest2): Item.READ via ViewStore.canView(io.jenkins.plugins.interactiveinput.view.ReviewDocument), else 404 (no existence leak). Two further gates keep this from becoming a general "serve arbitrary HTML from Jenkins" endpoint: it 404s unless the htmlRendering feature is on, and unless the document really is an HTML snapshot (ApiRootAction.htmlRenderable(io.jenkins.plugins.interactiveinput.view.ReviewDocument)) — a markdown or code document is never served this way.

      The bytes are untrusted, so the isolation lives entirely in the response headers — see SandboxedHtmlResponse, which serves them under Content-Security-Policy: sandbox allow-scripts (an opaque origin that cannot touch this Jenkins session, even if the URL is opened directly).

    • doDownload

      @GET public org.kohsuke.stapler.HttpResponse doDownload()
      GET /views/{id}/download — the current version's content as a file attachment.

      Read-only (no CSRF needed) and permission-checked exactly like doIndex(): Item.READ via ViewStore.canView(io.jenkins.plugins.interactiveinput.view.ReviewDocument), else 404 (no existence leak). The download name is the snapshot's basename, further sanitised by DownloadHttpResponse.

    • doDownloadGroup

      @GET public org.kohsuke.stapler.HttpResponse doDownloadGroup()
      GET /views/{id}/downloadGroup — every readable document published together with this one (same groupId on the same build) as a single ZIP; a lone document yields a one-entry archive.

      Read-only and permission-checked like doDownload(): the anchor document must be readable (Item.READ, else 404), and only co-group members the caller can also read are included (ViewStore.listForBuild(java.lang.String, int) already applies canView). ZIP entry names are sanitised (no CR/LF, no leading /, no ./.. segments) and de-duplicated.

    • doComments

      public org.kohsuke.stapler.HttpResponse doComments(org.kohsuke.stapler.StaplerRequest2 req)
      POST /views/{id}/comments — add an inline or general comment, optionally as a threaded reply (parentId) and/or with a display-only author label (authorLabel, or set automated:true to use the configured global label). The audit author is always the authenticated Jenkins identity — never taken from the request — so a label cannot spoof it.
    • doEdit

      public org.kohsuke.stapler.HttpResponse doEdit(org.kohsuke.stapler.StaplerRequest2 req)
      POST /views/{id}/edit — save an edit to the durable review copy as a new version.
    • doDecision

      public org.kohsuke.stapler.HttpResponse doDecision(org.kohsuke.stapler.StaplerRequest2 req)
      POST /views/{id}/decision — record approve / reject / acknowledge (resolves a waiting step).
    • doResolveComment

      public org.kohsuke.stapler.HttpResponse doResolveComment(org.kohsuke.stapler.StaplerRequest2 req)
      POST /views/{id}/resolveComment — toggle a comment's resolved flag.