diff --git a/src/Forms/HTMLEditor/HTMLEditorField.php b/src/Forms/HTMLEditor/HTMLEditorField.php index db8d08a05..3edd623f7 100644 --- a/src/Forms/HTMLEditor/HTMLEditorField.php +++ b/src/Forms/HTMLEditor/HTMLEditorField.php @@ -138,7 +138,8 @@ class HTMLEditorField extends TextareaField // Sanitise if requested $htmlValue = HTMLValue::create($this->Value()); if (HTMLEditorField::config()->sanitise_server_side) { - $santiser = HTMLEditorSanitiser::create(HTMLEditorConfig::get_active()); + $config = $this->getEditorConfig(); + $santiser = HTMLEditorSanitiser::create($config); $santiser->sanitise($htmlValue); } diff --git a/src/Forms/HTMLEditor/HTMLEditorSanitiser.php b/src/Forms/HTMLEditor/HTMLEditorSanitiser.php index a075d98fa..fa23c476b 100644 --- a/src/Forms/HTMLEditor/HTMLEditorSanitiser.php +++ b/src/Forms/HTMLEditor/HTMLEditorSanitiser.php @@ -287,10 +287,6 @@ class HTMLEditorSanitiser */ public function sanitise(HTMLValue $html) { - if (!$this->elements && !$this->elementPatterns) { - return; - } - $linkRelValue = $this->config()->get('link_rel_value'); $doc = $html->getDocument(); diff --git a/src/Forms/HTMLEditor/TinyMCEConfig.php b/src/Forms/HTMLEditor/TinyMCEConfig.php index 80621abd0..8b5076f39 100644 --- a/src/Forms/HTMLEditor/TinyMCEConfig.php +++ b/src/Forms/HTMLEditor/TinyMCEConfig.php @@ -250,13 +250,11 @@ class TinyMCEConfig extends HTMLEditorConfig implements i18nEntityProvider private static $image_size_presets = [ ]; /** - * TinyMCE JS settings + * Default TinyMCE JS options which apply to all new configurations. * * @link https://www.tiny.cloud/docs/tinymce/6/tinydrive-getting-started/#configure-the-required-tinymce-options - * - * @var array */ - protected $settings = [ + private static array $default_options = [ 'fix_list_elements' => true, // https://www.tiny.cloud/docs/tinymce/6/content-filtering/#fix_list_elements 'formats' => [ 'alignleft' => [ @@ -311,8 +309,24 @@ class TinyMCEConfig extends HTMLEditorConfig implements i18nEntityProvider 'promotion' => false, 'upload_folder_id' => null, // Set folder ID for insert media dialog 'link_default_target' => '_blank', // https://www.tiny.cloud/docs/tinymce/6/autolink/#example-using-link_default_target + // Default set of valid_elements which apply for all new configurations + 'valid_elements' => "@[id|class|style|title],a[id|rel|rev|dir|tabindex|accesskey|type|name|href|target|title" + . "|class],-strong/-b[class],-em/-i[class],-strike[class],-u[class],#p[id|dir|class|align|style],-ol[class]," + . "-ul[class],-li[class],br,img[id|dir|longdesc|usemap|class|src|border|alt=|title|hspace|vspace|width|height|align|name|data*]," + . "-sub[class],-sup[class],-blockquote[dir|class],-cite[dir|class|id|title]," + . "-table[cellspacing|cellpadding|width|height|class|align|summary|dir|id|style]," + . "-tr[id|dir|class|rowspan|width|height|align|valign|bgcolor|background|bordercolor|style]," + . "tbody[id|class|style],thead[id|class|style],tfoot[id|class|style]," + . "#td[id|dir|class|colspan|rowspan|width|height|align|valign|scope|style]," + . "-th[id|dir|class|colspan|rowspan|width|height|align|valign|scope|style],caption[id|dir|class]," + . "-div[id|dir|class|align|style],-span[class|align|style],-pre[class|align],address[class|align]," + . "-h1[id|dir|class|align|style],-h2[id|dir|class|align|style],-h3[id|dir|class|align|style]," + . "-h4[id|dir|class|align|style],-h5[id|dir|class|align|style],-h6[id|dir|class|align|style],hr[class]," + . "dd[id|class|title|dir],dl[id|class|title|dir],dt[id|class|title|dir]," ]; + protected $settings = []; + /** * Holder list of enabled plugins * @@ -337,6 +351,11 @@ class TinyMCEConfig extends HTMLEditorConfig implements i18nEntityProvider */ protected $theme = 'silver'; + public function __construct() + { + $this->settings = static::config()->get('default_options'); + } + /** * Get the theme * diff --git a/tests/php/Forms/HTMLEditor/HTMLEditorFieldTest.php b/tests/php/Forms/HTMLEditor/HTMLEditorFieldTest.php index 2abe550aa..b046a1fd2 100644 --- a/tests/php/Forms/HTMLEditor/HTMLEditorFieldTest.php +++ b/tests/php/Forms/HTMLEditor/HTMLEditorFieldTest.php @@ -12,6 +12,7 @@ use SilverStripe\Control\Director; use SilverStripe\Core\Config\Config; use SilverStripe\Dev\CSSContentParser; use SilverStripe\Dev\FunctionalTest; +use SilverStripe\Forms\HTMLEditor\HTMLEditorConfig; use SilverStripe\Forms\HTMLEditor\HTMLEditorField; use SilverStripe\Forms\HTMLEditor\TinyMCEConfig; use SilverStripe\Forms\HTMLReadonlyField; @@ -278,4 +279,41 @@ EOS $this->assertEquals("auto", $data_config->height, 'Config height is not set'); $this->assertEquals("60px", $data_config->row_height, 'Config row_height is not set'); } + + public function testFieldConfigSanitization() + { + $obj = TestObject::create(); + $editor = HTMLEditorField::create('Content'); + $defaultValidElements = [ + '@[id|class|style|title|data*]', + 'a[id|rel|dir|tabindex|accesskey|type|name|href|target|title|class]', + '-strong/-b[class]', + '-em/-i[class]', + '-ol[class]', + '#p[id|dir|class|align|style]', + '-li[class]', + 'br', + '-span[class|align|style]', + '-ul[class]', + '-h3[id|dir|class|align|style]', + '-h2[id|dir|class|align|style]', + 'hr[class]', + ]; + $restrictedConfig = HTMLEditorConfig::get('restricted'); + $restrictedConfig->setOption('valid_elements', implode(',', $defaultValidElements)); + $editor->setEditorConfig($restrictedConfig); + + $expectedHtmlString = '
standard text
Header'; + $htmlValue = 'standard text
Header |
Leave Alone
standard text
text |
---|
Header |