Class SandboxedHtmlResponse
- All Implemented Interfaces:
org.kohsuke.stapler.HttpResponse
interactiveView HTML snapshot for display inside a sandboxed frame, so a
reviewer can look at a generated report (a Robot Framework log.html, an Allure/pytest report,
…) instead of only its escaped source.
The content is generated by a pipeline and is therefore untrusted, so the whole point of this class
is the header set below. It is the counterpart of DownloadHttpResponse, which serves the same
bytes as an attachment precisely so that a browser never renders them in the Jenkins origin.
Why Content-Security-Policy: sandbox
sandbox allow-scripts applies the <iframe sandbox> rules to this document.
Because allow-same-origin is deliberately absent, the browser gives the document a unique
opaque origin, which means its scripts:
- cannot reach the embedding Jenkins page's DOM (it is cross-origin to them);
- cannot read the session cookie,
localStorageorsessionStorage; - cannot read a CSRF crumb — Jenkins sends no CORS headers, so a cross-origin read is refused — and therefore cannot forge an authenticated mutating request; and
- cannot submit a form, open a window, or navigate the reviewer's tab, since
allow-forms,allow-popupsandallow-top-navigationare all withheld.
Sending it as a header (rather than relying only on the frame's sandbox attribute)
is what makes the endpoint safe to open directly: pasting the URL into the address bar still yields an
opaque-origin document, so it cannot script the Jenkins origin either way. The frame adds the same
sandbox attribute, giving two independent enforcement points.
Scripts are permitted on purpose: report generators embed their entire payload as JavaScript, so a
script-free render shows nothing useful (a Robot log.html degrades to its "JavaScript
disabled" error). The residual risk of allow-scripts — outbound requests, and misleading
content drawn inside the frame — is bounded by the opaque origin and accepted for content the
operator's own pipeline produced; an operator who disagrees turns the htmlRendering feature
off and keeps HTML source-only.
No other CSP directive is set: a self-contained report relies on inline <script>, inline
<style> and data: URIs, so a default-src/script-src restriction here
would break the very files this exists to display. frame-ancestors 'self' keeps another site
from embedding the endpoint, and nosniff plus an explicit charset stop MIME/encoding
guessing.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidgenerateResponse(org.kohsuke.stapler.StaplerRequest2 req, org.kohsuke.stapler.StaplerResponse2 rsp, Object node) Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface org.kohsuke.stapler.HttpResponse
generateResponse
-
Constructor Details
-
SandboxedHtmlResponse
- Parameters:
html- the snapshot's HTML source (serialised as UTF-8, which thecharsetbelow declares so the browser never has to guess the encoding)
-
-
Method Details
-
generateResponse
public void generateResponse(org.kohsuke.stapler.StaplerRequest2 req, org.kohsuke.stapler.StaplerResponse2 rsp, Object node) throws IOException - Specified by:
generateResponsein interfaceorg.kohsuke.stapler.HttpResponse- Throws:
IOException
-