Skip to content

SK-2449 ga ready render zip file in js sdk (#734) - #737

Merged
skyflow-bharti merged 3 commits into
mainfrom
release/26.9.22
Sep 22, 2026
Merged

skyflow-bharti merged 3 commits into
mainfrom
release/26.9.22

Conversation

@skyflow-bharti

@skyflow-bharti skyflow-bharti commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

SK-2449: Render zip files in composable reveal elements

Adds opt-in zip rendering to the composable reveal file element. When a stored file is a .zip and the caller passes renderFile({ zipRender: true }), the SDK unzips the archive inside the secure iframe and shows a list-detail viewer: the extracted files on the left, a preview of the selected file on the right, with optional per-file download. Nothing changes for existing single-file renders. The branch also carries the SK-3149 preserve-filename fix so the two do not conflict when merged.

Why

Customers store archives of sensitive documents in a file column and need end users to review the contents without downloading and unzipping locally, which defeats the no-download model. Today the SDK can only reveal a zip as one opaque file.

Customers cannot build this themselves. ServiceNow, the driving case, embeds the SDK inside a Shadow DOM where each reveal element is an isolated iframe. Coordinating unzip, selection state and previews across iframes from the host page is brittle and would expose raw bytes to the page. The only place a zip viewer can live safely is inside the Skyflow-controlled frame.

An earlier prototype shipped as 2.8.0-beta.3 in February. It rendered any file whose type contained "zip", inflated every entry up front, allowed download with no policy check and no origin check, never revoked blob URLs, and had no tests. This PR replaces it rather than extending it.

Goal

  • renderFile(options) on composable reveal elements accepts zipRender, layout, allowDownload, autoSelectFirst and labelMode. All keys are validated; unsupported values are rejected before any network call.
  • layout and labelMode take enums, ZipRenderLayout and ZipLabelMode, exposed on the Skyflow global and exported from the npm package.
  • The viewer lists files by basename with the full path on hover and disambiguates duplicate names with the parent folder. labelMode: PATH shows full paths. Long unbreakable names truncate with an ellipsis inside the chip.
  • downloadCurrentFile() downloads the previewed file, only when allowDownload: true, only for requests from the client origin, and never for executable or archive types.
  • The success response carries fileMetadata for the archive and unZippedFilesMetadata with name, size and type per entry. RenderFileResponse and the new UnzippedFileMetadata type describe this for TypeScript users.
  • Three scoped style hooks, zipNavStyles, zipNavListItemStyles and zipPanelStyles, style the list, its items including the selected state, and the preview panel. In-pane messages inherit the element's errorTextStyles.
  • Hardening: exact zip MIME detection, lazy per-entry extraction so large archives stay responsive, blob URLs revoked on re-render and teardown, a stale-response guard for back-to-back calls, and dangerous types listed but never previewed.

Non-goals, deferred by product decision: whole-zip download, nested-zip extraction, folder-tree navigation, grid or carousel layouts, server-side transcoding of unsupported types, and zip rendering on the plain (non-composable) reveal element.

Testing

  • 44 unit tests in the new reveal-frame-zip suite cover detection and opt-in, every option and its validation, enum acceptance, label modes and collisions, lazy extraction with a 300-file archive, the download policy paths, dangerous-type blocking, empty and corrupt archives, style merging, metadata shape, chip truncation, and re-render teardown.
  • Validator tests cover validateRenderOptions and isDangerousFileType, including undefined and null inputs.
  • Preserve-filename regressions are covered on both FILE_INPUT and MULTI_FILE_INPUT paths.
  • Full package suite: 53 suites, 1516 tests passing.
  • A consumer-style TypeScript snippet was compiled against the public entry point to confirm the exported types describe the real response and that the renamed size key is enforced.
  • Manual: samples/using-script-tag/zip-file-render.html is a new documented sample; a scenario-driven page was used locally to walk all fourteen option combinations against a Blitz vault, including invalid options and race conditions.

Concerns for release: unZippedFilesMetadata and the enums are new public surface, additive only. The one behavioural change outside zip is the SK-3149 fix, where uploadMultipleFiles() with an empty selection now rejects with the standard No File Selected error inside errorResponse instead of a bare string. Anyone string-matching the old text must adjust; the README never documented the old shape.

Tech debt

  • Adds jszip 3.10.1 as a pinned runtime dependency. The lock file is updated.
  • Removes the duplicate INVALID_FILE_NAMES message and fixes a case A || B label in element-options that silently matched only FILE_INPUT.
  • Tests are not type-checked in this repo, so the exported-type check above is not automated. A tsd style check in CI would close that gap.
  • The composable-internal render response listener and the collect frame controller still have low branch coverage; they predate this PR and are tracked separately.

* SK-3149 fix file preserve name in multi file input element (#733)

* SK-2449 zip render support

* SK-2449 add preserve file name fix

* SK-2449 update lock file for jszip

* SK-2449 render zip file in js sdk (#735)

* SK-2449 zip render support

* SK-2449 add preserve file name fix

* SK-2449 update lock file for jszip

* SK-2449 fix error msg

* SK-2449 make consistent metadata keynames

* SK-2449 update styles

* SK-2449 update response type
@github-actions

Copy link
Copy Markdown

✅ Gitleaks Findings: No secrets detected. Safe to proceed!

@github-actions

Copy link
Copy Markdown

Semgrep Findings: Issues with Error level severity are found (Error is Highest severity in Semgrep), Please resolve the issues before merging.

@github-actions

Copy link
Copy Markdown

✅ Gitleaks Findings: No secrets detected. Safe to proceed!

@github-actions

Copy link
Copy Markdown

Semgrep Findings: Issues with Error level severity are found (Error is Highest severity in Semgrep), Please resolve the issues before merging.

@github-actions

Copy link
Copy Markdown

✅ Gitleaks Findings: No secrets detected. Safe to proceed!

@github-actions

Copy link
Copy Markdown

Semgrep Findings: Issues with Error level severity are found (Error is Highest severity in Semgrep), Please resolve the issues before merging.

@skyflow-bharti
skyflow-bharti merged commit 111bf37 into main Sep 22, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants