Issue
When a strict Content Security Policy (CSP) is applied to an application (for example, Content-Security-Policy: style-src 'self'), features of the Rich Text widget related to nested components (such as tables) or editing/viewing code do not render or function correctly.
Environment
Rich Text v4.12.0 and older
Cause
The code viewer functionality of the Rich Text widget relies on a third-party library that is not fully CSP-compliant. Because the library injects inline styles, these are blocked when style-src 'self' is enforced, which results in a broken editor layout. The same inline-style dependency also affects the rendering and saving of nested components such as tables and their cell/table properties.
Solution/Workaround
The Rich Text widget version 5.0.0 and newer uses a different, CSP-compliant library and a different approach for nested components such as tables. To resolve the issue:
- Download and install Rich Text version 5.0.0 or newer from the Mendix Marketplace.
- Check the Style data format setting of the Rich Text widget and set it to class.
- Verify that the Rich Text content is not rendered outside of the widget (for example, through an HTML element widget), as this bypasses the widget styling.
Internal information related
- 281474
- CJZ85RLTA/p1775808965418049
Additional information
Mendix documentation:
0 Comments