feat(preview): render XLSX spreadsheets in the file-preview overlay

xlsx files were download-only. Add a read-only, virtualized preview (sheet
tabs, number formats, merges, theme colours) parsed entirely in a browser
Web Worker with exceljs and fflate, loaded only when a spreadsheet is
opened. The workbook is checked against ZIP-bomb, entry and cell limits
before exceljs loads; cell text is written with textContent, formulas are
never evaluated and nothing referenced by the workbook is fetched. On the
server xlsx only joins the existing allowlist and classification, with a
10 MB cap on ?preview=true. xls and ods stay download-only.
This commit is contained in:
Aamer Akhter
2026-09-26 23:13:21 -04:00
parent 45ea2e1d32
commit 0b122e2c76
27 changed files with 3765 additions and 13 deletions
+130
View File
@@ -19088,3 +19088,133 @@ html[data-session-list="sidebar"][data-sidebar="collapsed"] .btn-sidebar-toggle
font-size: 13px;
color: var(--text-muted);
}
/* XLSX preview in the file-preview overlay (spreadsheet-preview.js). Read-only; cells are
absolutely positioned inside a virtualized grid, so only the visible tile is in the DOM. */
.spreadsheet-preview-shell {
display: flex;
flex-direction: column;
width: 100%;
height: 100%;
min-height: 0;
background: var(--bg-primary);
}
.spreadsheet-sheet-tabs {
display: flex;
flex: 0 0 auto;
gap: 2px;
overflow-x: auto;
padding: 6px 8px 0;
border-bottom: 1px solid var(--border);
}
.spreadsheet-sheet-tab {
flex: 0 0 auto;
min-width: 80px;
max-width: 220px;
padding: 6px 12px;
overflow: hidden;
color: var(--text-secondary);
text-overflow: ellipsis;
white-space: nowrap;
border: 1px solid transparent;
border-bottom: 0;
border-radius: 6px 6px 0 0;
background: transparent;
}
.spreadsheet-sheet-tab[aria-selected='true'] {
color: var(--text-primary);
border-color: var(--border);
background: var(--bg-secondary);
}
.spreadsheet-preview-notice {
flex: 0 0 auto;
padding: 5px 10px;
color: var(--warning, #f59e0b);
font-size: 12px;
border-bottom: 1px solid var(--border);
}
.spreadsheet-grid {
position: relative;
flex: 1 1 auto;
min-height: 220px;
overflow: auto;
overscroll-behavior: contain;
}
.spreadsheet-grid-spacer,
.spreadsheet-cells,
.spreadsheet-headings {
position: absolute;
top: 0;
left: 0;
}
.spreadsheet-row-heading,
.spreadsheet-column-heading {
position: absolute;
z-index: 2;
color: var(--text-secondary);
font-size: 11px;
line-height: 18px;
text-align: center;
background: var(--bg-secondary);
border: 1px solid var(--border);
pointer-events: none;
}
.spreadsheet-row-heading {
left: 0;
width: 36px;
height: 20px;
}
.spreadsheet-column-heading {
top: 0;
width: 64px;
height: 20px;
}
.spreadsheet-empty-sheet {
position: sticky;
top: 20px;
left: 36px;
z-index: 3;
width: max-content;
padding: 24px;
color: var(--text-secondary);
background: var(--bg-primary);
}
.spreadsheet-cell {
position: absolute;
min-width: 0;
padding: 2px 5px;
overflow: hidden;
color: var(--text-primary);
font-size: 12px;
line-height: 16px;
text-overflow: ellipsis;
white-space: nowrap;
border-right: 1px solid var(--border);
border-bottom: 1px solid var(--border);
background: var(--bg-primary);
}
.spreadsheet-preview-message {
display: grid;
min-height: 220px;
place-items: center;
padding: 24px;
color: var(--text-secondary);
text-align: center;
}
.spreadsheet-preview-message.error {
color: var(--danger, #ef4444);
}