SK-2449 ga ready render zip file in js sdk (#734) - #737
Merged
Merged
Conversation
* SK-3149 fix file preserve name in multi file input element (#733) * SK-2449 zip render support * SK-2449 add preserve file name fix * SK-2449 update lock file for jszip * SK-2449 render zip file in js sdk (#735) * SK-2449 zip render support * SK-2449 add preserve file name fix * SK-2449 update lock file for jszip * SK-2449 fix error msg * SK-2449 make consistent metadata keynames * SK-2449 update styles * SK-2449 update response type
|
✅ Gitleaks Findings: No secrets detected. Safe to proceed! |
|
Semgrep Findings: Issues with Error level severity are found (Error is Highest severity in Semgrep), Please resolve the issues before merging. |
|
✅ Gitleaks Findings: No secrets detected. Safe to proceed! |
|
Semgrep Findings: Issues with Error level severity are found (Error is Highest severity in Semgrep), Please resolve the issues before merging. |
yaswanth-pula-skyflow
previously approved these changes
Sep 22, 2026
|
✅ Gitleaks Findings: No secrets detected. Safe to proceed! |
|
Semgrep Findings: Issues with Error level severity are found (Error is Highest severity in Semgrep), Please resolve the issues before merging. |
yaswanth-pula-skyflow
approved these changes
Sep 22, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
SK-2449: Render zip files in composable reveal elements
Adds opt-in zip rendering to the composable reveal file element. When a stored file is a
.zipand the caller passesrenderFile({ zipRender: true }), the SDK unzips the archive inside the secure iframe and shows a list-detail viewer: the extracted files on the left, a preview of the selected file on the right, with optional per-file download. Nothing changes for existing single-file renders. The branch also carries the SK-3149 preserve-filename fix so the two do not conflict when merged.Why
Customers store archives of sensitive documents in a file column and need end users to review the contents without downloading and unzipping locally, which defeats the no-download model. Today the SDK can only reveal a zip as one opaque file.
Customers cannot build this themselves. ServiceNow, the driving case, embeds the SDK inside a Shadow DOM where each reveal element is an isolated iframe. Coordinating unzip, selection state and previews across iframes from the host page is brittle and would expose raw bytes to the page. The only place a zip viewer can live safely is inside the Skyflow-controlled frame.
An earlier prototype shipped as
2.8.0-beta.3in February. It rendered any file whose type contained "zip", inflated every entry up front, allowed download with no policy check and no origin check, never revoked blob URLs, and had no tests. This PR replaces it rather than extending it.Goal
renderFile(options)on composable reveal elements acceptszipRender,layout,allowDownload,autoSelectFirstandlabelMode. All keys are validated; unsupported values are rejected before any network call.layoutandlabelModetake enums,ZipRenderLayoutandZipLabelMode, exposed on theSkyflowglobal and exported from the npm package.labelMode: PATHshows full paths. Long unbreakable names truncate with an ellipsis inside the chip.downloadCurrentFile()downloads the previewed file, only whenallowDownload: true, only for requests from the client origin, and never for executable or archive types.fileMetadatafor the archive andunZippedFilesMetadatawithname,sizeandtypeper entry.RenderFileResponseand the newUnzippedFileMetadatatype describe this for TypeScript users.zipNavStyles,zipNavListItemStylesandzipPanelStyles, style the list, its items including the selected state, and the preview panel. In-pane messages inherit the element'serrorTextStyles.Non-goals, deferred by product decision: whole-zip download, nested-zip extraction, folder-tree navigation, grid or carousel layouts, server-side transcoding of unsupported types, and zip rendering on the plain (non-composable) reveal element.
Testing
reveal-frame-zipsuite cover detection and opt-in, every option and its validation, enum acceptance, label modes and collisions, lazy extraction with a 300-file archive, the download policy paths, dangerous-type blocking, empty and corrupt archives, style merging, metadata shape, chip truncation, and re-render teardown.validateRenderOptionsandisDangerousFileType, including undefined and null inputs.sizekey is enforced.samples/using-script-tag/zip-file-render.htmlis a new documented sample; a scenario-driven page was used locally to walk all fourteen option combinations against a Blitz vault, including invalid options and race conditions.Concerns for release:
unZippedFilesMetadataand the enums are new public surface, additive only. The one behavioural change outside zip is the SK-3149 fix, whereuploadMultipleFiles()with an empty selection now rejects with the standardNo File Selectederror insideerrorResponseinstead of a bare string. Anyone string-matching the old text must adjust; the README never documented the old shape.Tech debt
jszip3.10.1 as a pinned runtime dependency. The lock file is updated.INVALID_FILE_NAMESmessage and fixes acase A || Blabel in element-options that silently matched only FILE_INPUT.tsdstyle check in CI would close that gap.