mirror of
https://github.com/makeplane/plane.git
synced 2026-09-01 19:48:42 +02:00
* [WEB-7888] fix(security): normalize href before protocol check in CustomLinkExtension (GHSA-v2vv-7wq3-8w2j)
The existing startsWith("javascript:") guard in parseHTML() and renderHTML()
is bypassable with a whitespace prefix (e.g. "\tjavascript:alert(1)"). Per the
WHATWG URL spec, browsers strip ASCII Tab/LF/CR from URL strings during parsing,
so the whitespace-prefixed href passes the guard, is rendered into the DOM
verbatim, and executes when clicked (browser strips the tab → javascript: fires).
Add isDangerousHref() helper that strips Tab/LF/CR and leading C0 controls
before the protocol check, replicating the browser's normalization. Replace
both naive startsWith checks in parseHTML() and renderHTML() with this helper.
Add a defence-in-depth guard in clickHandler.ts that rejects
javascript:/data:/vbscript: hrefs before window.open() — link.href is the
browser-resolved URL (whitespace already stripped), so a regex check there
catches any URI that bypasses the parse/render-time guards.
Co-authored-by: Plane AI <noreply@plane.so>
* [WEB-7888] fix: align clickHandler blocked-scheme list with isValidHttpUrl policy
Add file: and about: to the clickHandler protocol guard to match the
blocked-scheme contract in isValidHttpUrl, avoiding policy drift.
Co-authored-by: Plane AI <noreply@plane.so>
---------
Co-authored-by: Plane AI <noreply@plane.so>
@plane/editor
Description
The @plane/editor package serves as the foundation for our editor system. It provides the base functionality for our other editor packages, but it will not be used directly in any of the projects but only for extending other editors.
Utilities
We provide a wide range of utilities for extending the core itself.
- Merging classes and custom styling
- Adding new extensions
- Adding custom props
- Base menu items, and their commands
This allows for extensive customization and flexibility in the Editors created using our editor-core package.
Here's a detailed overview of what's exported
-
useEditor - A hook that you can use to extend the Plane editor.
Prop Type Description extensionsExtension[]An array of custom extensions you want to add into the editor to extend it's core features editorPropsEditorPropsExtend the editor props by passing in a custom props object uploadFile(file: File) => Promise<string>A function that handles file upload. It takes a file as input and handles the process of uploading that file. deleteFile(assetUrlWithWorkspaceId: string) => Promise<any>A function that handles deleting an image. It takes the asset url from your bucket and handles the process of deleting that image. valuehtml stringThe initial content of the editor. debouncedUpdatesEnabledbooleanIf set to true, the onChangeevent handler is debounced, meaning it will only be invoked after the specified delay (default 1500ms) once the user has stopped typing.onChange(json: any, html: string) => voidThis function is invoked whenever the content of the editor changes. It is passed the new content in both JSON and HTML formats. setIsSubmitting(isSubmitting: "submitting" | "submitted" | "saved") => voidThis function is called to update the submission status. setShouldShowAlert(showAlert: boolean) => voidThis function is used to show or hide an alert in case of content not being "saved". forwardedRefanyPass this in whenever you want to control the editor's state from an external component -
useReadOnlyEditor - A hook that can be used to extend a Read Only instance of the core editor.
Prop Type Description valuestringThe initial content of the editor. forwardedRefanyPass this in whenever you want to control the editor's state from an external component extensionsExtension[]An array of custom extensions you want to add into the editor to extend it's core features editorPropsEditorPropsExtend the editor props by passing in a custom props object -
Items and Commands - H1, H2, H3, task list, quote, code block, etc's methods.
-
UI Wrappers
EditorContainer- Wrap your Editor Container with this to apply base classes and styles.EditorContentWrapper- Use this to get Editor's Content and base menus.
- Extending with Custom Styles
const customEditorClassNames = getEditorClassNames({
noBorder,
borderOnFocus,
customClassName,
});
Core features
- Content Trimming: The Editor’s content is now automatically trimmed of empty line breaks from the start and end before submitting it to the backend. This ensures cleaner, more consistent data.
- Value Cleaning: The Editor’s value is cleaned at the editor core level, eliminating the need for additional validation before sending from our app. This results in cleaner code and less potential for errors.
- Turbo Pipeline: Added a turbo pipeline for both dev and build tasks for projects depending on the editor package.
Base extensions included
- BulletList
- OrderedList
- Blockquote
- Code
- Gapcursor
- Link
- Image
- Basic Marks
- Underline
- TextStyle
- Color
- TaskList
- Markdown
- Table