Class SandboxedHtmlResponse

java.lang.Object
io.jenkins.plugins.interactiveinput.rest.SandboxedHtmlResponse
All Implemented Interfaces:
org.kohsuke.stapler.HttpResponse

public class SandboxedHtmlResponse extends Object implements org.kohsuke.stapler.HttpResponse
Serves an interactiveView HTML snapshot for display inside a sandboxed frame, so a reviewer can look at a generated report (a Robot Framework log.html, an Allure/pytest report, …) instead of only its escaped source.

The content is generated by a pipeline and is therefore untrusted, so the whole point of this class is the header set below. It is the counterpart of DownloadHttpResponse, which serves the same bytes as an attachment precisely so that a browser never renders them in the Jenkins origin.

Why Content-Security-Policy: sandbox

sandbox allow-scripts applies the <iframe sandbox> rules to this document. Because allow-same-origin is deliberately absent, the browser gives the document a unique opaque origin, which means its scripts:

  • cannot reach the embedding Jenkins page's DOM (it is cross-origin to them);
  • cannot read the session cookie, localStorage or sessionStorage;
  • cannot read a CSRF crumb — Jenkins sends no CORS headers, so a cross-origin read is refused — and therefore cannot forge an authenticated mutating request; and
  • cannot submit a form, open a window, or navigate the reviewer's tab, since allow-forms, allow-popups and allow-top-navigation are all withheld.

Sending it as a header (rather than relying only on the frame's sandbox attribute) is what makes the endpoint safe to open directly: pasting the URL into the address bar still yields an opaque-origin document, so it cannot script the Jenkins origin either way. The frame adds the same sandbox attribute, giving two independent enforcement points.

Scripts are permitted on purpose: report generators embed their entire payload as JavaScript, so a script-free render shows nothing useful (a Robot log.html degrades to its "JavaScript disabled" error). The residual risk of allow-scripts — outbound requests, and misleading content drawn inside the frame — is bounded by the opaque origin and accepted for content the operator's own pipeline produced; an operator who disagrees turns the htmlRendering feature off and keeps HTML source-only.

No other CSP directive is set: a self-contained report relies on inline <script>, inline <style> and data: URIs, so a default-src/script-src restriction here would break the very files this exists to display. frame-ancestors 'self' keeps another site from embedding the endpoint, and nosniff plus an explicit charset stop MIME/encoding guessing.

  • Constructor Details

    • SandboxedHtmlResponse

      public SandboxedHtmlResponse(@NonNull String html)
      Parameters:
      html - the snapshot's HTML source (serialised as UTF-8, which the charset below declares so the browser never has to guess the encoding)
  • Method Details

    • generateResponse

      public void generateResponse(org.kohsuke.stapler.StaplerRequest2 req, org.kohsuke.stapler.StaplerResponse2 rsp, Object node) throws IOException
      Specified by:
      generateResponse in interface org.kohsuke.stapler.HttpResponse
      Throws:
      IOException