feat(actions): Add artifact preview in Actions run view (#36754)

Closes https://github.com/go-gitea/gitea/issues/33579.

Adds browser previews for Actions artifacts. Selecting an artifact opens
its file browser; selecting a file renders it in the same tab. The ZIP
download remains available separately.

Previews require sign-in and read access to the run. Text, image and PDF
files are supported; rendered HTML and JavaScript run in a sandboxed
frame and are labeled as automatically generated. The frame loads files
from a signed link that expires after an hour, because its requests
carry no session cookie. `[actions] ARTIFACT_PREVIEW_MAX_SIZE` limits
total previewable artifact size (`0` disables previews; `-1` removes the
limit); individual files also follow `[ui] MAX_DISPLAY_FILE_SIZE`.

<img width="1803" height="913" alt="image"
src="https://github.com/user-attachments/assets/a38fd704-2244-44fa-9181-c695ecbe0276"
/>

Docs: https://gitea.com/gitea/docs/pulls/533

---------

Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: Zettat123 <zettat123@gmail.com>
This commit is contained in:
bircni
2026-09-26 09:42:36 +02:00
committed by GitHub
parent 857d3d3df3
commit 5a56e118e4
22 changed files with 971 additions and 68 deletions
+3 -3
View File
@@ -39,9 +39,9 @@ type ServeHeaderOptions struct {
const (
// Disable JS execution on the same origin, since we serve the file from the same origin as Gitea server.
// This rule can be relaxed in the future as long as it is properly sandboxed.
// "style-src" is for SVG inline styles (from Display SVG files as images instead of text #14101)
serveHeaderCspDefault = "default-src 'none'; style-src 'unsafe-inline'; sandbox"
// 'unsafe-inline' is needed by inline script and SVG inline styles (from Display SVG files as images instead of text #14101),
// So we don't set any "*-src" rule here, just use sandbox.
serveHeaderCspDefault = "sandbox allow-scripts allow-modals allow-popups allow-downloads"
// No sandbox attribute for PDF as it breaks rendering in at least Safari.
// This should generally be safe as scripts inside PDF can not escape the PDF document.
+2 -1
View File
@@ -131,7 +131,8 @@ func TestServeSetHeaderContentRelated(t *testing.T) {
}
// make sure sandboxed
require.Contains(t, serveHeaderCspDefault, "; sandbox")
require.Contains(t, serveHeaderCspDefault, "sandbox")
require.NotContains(t, serveHeaderCspDefault, "allow-same-origin")
}
func TestServeSetHeaders(t *testing.T) {