feat(actions): Add artifact preview in Actions run view (#36754)

Closes https://github.com/go-gitea/gitea/issues/33579.

Adds browser previews for Actions artifacts. Selecting an artifact opens
its file browser; selecting a file renders it in the same tab. The ZIP
download remains available separately.

Previews require sign-in and read access to the run. Text, image and PDF
files are supported; rendered HTML and JavaScript run in a sandboxed
frame and are labeled as automatically generated. The frame loads files
from a signed link that expires after an hour, because its requests
carry no session cookie. `[actions] ARTIFACT_PREVIEW_MAX_SIZE` limits
total previewable artifact size (`0` disables previews; `-1` removes the
limit); individual files also follow `[ui] MAX_DISPLAY_FILE_SIZE`.

<img width="1803" height="913" alt="image"
src="https://github.com/user-attachments/assets/a38fd704-2244-44fa-9181-c695ecbe0276"
/>

Docs: https://gitea.com/gitea/docs/pulls/533

---------

Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: Zettat123 <zettat123@gmail.com>
This commit is contained in:
bircni
2026-09-26 09:42:36 +02:00
committed by GitHub
parent 857d3d3df3
commit 5a56e118e4
22 changed files with 971 additions and 68 deletions
+3 -3
View File
@@ -39,9 +39,9 @@ type ServeHeaderOptions struct {
const (
// Disable JS execution on the same origin, since we serve the file from the same origin as Gitea server.
// This rule can be relaxed in the future as long as it is properly sandboxed.
// "style-src" is for SVG inline styles (from Display SVG files as images instead of text #14101)
serveHeaderCspDefault = "default-src 'none'; style-src 'unsafe-inline'; sandbox"
// 'unsafe-inline' is needed by inline script and SVG inline styles (from Display SVG files as images instead of text #14101),
// So we don't set any "*-src" rule here, just use sandbox.
serveHeaderCspDefault = "sandbox allow-scripts allow-modals allow-popups allow-downloads"
// No sandbox attribute for PDF as it breaks rendering in at least Safari.
// This should generally be safe as scripts inside PDF can not escape the PDF document.
+2 -1
View File
@@ -131,7 +131,8 @@ func TestServeSetHeaderContentRelated(t *testing.T) {
}
// make sure sandboxed
require.Contains(t, serveHeaderCspDefault, "; sandbox")
require.Contains(t, serveHeaderCspDefault, "sandbox")
require.NotContains(t, serveHeaderCspDefault, "allow-same-origin")
}
func TestServeSetHeaders(t *testing.T) {
+3
View File
@@ -43,6 +43,8 @@ var (
// transaction at once per Gitea instance, to avoid a thundering herd when many
// runners poll together. It is a per-process limit, not a cluster-wide one.
MaxConcurrentTaskPicks int `ini:"MAX_CONCURRENT_TASK_PICKS"`
ArtifactPreviewMaxSize int64 `ini:"ARTIFACT_PREVIEW_MAX_SIZE"`
}{
Enabled: true,
DefaultActionsURL: defaultActionsURLGitHub,
@@ -51,6 +53,7 @@ var (
ScopedWorkflowDirs: []string{".gitea/scoped_workflows"},
MaxRerunAttempts: defaultMaxRerunAttempts,
MaxConcurrentTaskPicks: defaultMaxConcurrentTaskPicks,
ArtifactPreviewMaxSize: 10 * 1024 * 1024,
LogRetentionDays: defaultLogRetentionDays,
ArtifactRetentionDays: defaultArtifactRetentionDays,
RunRetentionDays: defaultRunRetentionDays,