refactor: markup render (#38864)

1. add missing CSP header to api & web render endpoints.
2. make jupyter render skip post-processors, nothing to process
3. make ShortLinkProcessor correctly validate URL schemes and respect
the CustomURLSchemes setting
This commit is contained in:
wxiaoguang
2026-08-12 00:01:02 +08:00
committed by GitHub
parent eeeb5d7c7b
commit 938cde959e
25 changed files with 255 additions and 172 deletions
+3
View File
@@ -64,6 +64,9 @@ func RenderFile(ctx *context.Context) {
extRendererOpts := extRenderer.GetExternalRendererOptions()
if extRendererOpts.ContentSandbox != "" {
ctx.Resp.Header().Add("Content-Security-Policy", "sandbox "+extRendererOpts.ContentSandbox)
} else {
// if no sandbox, just apply the same CSP as a general Gitea web page
ctx.SetHeaderContentSecurityPolicyGeneral()
}
err = markup.RenderWithRenderer(rctx, renderer, rendererInput, ctx.Resp)