<-- Back

Rich Text widget viewing/editing code and table properties do not work correctly under a strict Content Security Policy

Issue

When a strict Content Security Policy (CSP) is applied to an application (for example, Content-Security-Policy: style-src 'self'), features of the Rich Text widget related to nested components (such as tables) or editing/viewing code do not render or function correctly. 

Environment

Rich Text v4.12.0 and older

Cause

The code viewer functionality of the Rich Text widget relies on a third-party library that is not fully CSP-compliant. Because the library injects inline styles, these are blocked when style-src 'self' is enforced, which results in a broken editor layout. The same inline-style dependency also affects the rendering and saving of nested components such as tables and their cell/table properties.

Solution/Workaround

The Rich Text widget version 5.0.0 and newer uses a different, CSP-compliant library and a different approach for nested components such as tables. To resolve the issue:

  1. Download and install Rich Text version 5.0.0 or newer from the Mendix Marketplace.
  2. Check the Style data format setting of the Rich Text widget and set it to class.
  3. Verify that the Rich Text content is not rendered outside of the widget (for example, through an HTML element widget), as this bypasses the widget styling.

Internal information related

  • 281474
  • CJZ85RLTA/p1775808965418049

Additional information

Mendix documentation:

Have more questions? Submit a request

0 Comments

Article is closed for comments.

To provide feedback, please open a ticket here. Don't forget to include the article's URL along with the feedback you would like to provide.