Skip to content

Releases: linkrobins/html-widget

v1.3.0

Choose a tag to compare

@karl-bullock karl-bullock released this 27 Sep 19:29
4d5f828

Embeds are back, for the hosts you choose

Version 1.1.0 started sanitising the widget's HTML, and that stripped every <iframe> along with it. It closed a real hole, but it also took away the main reason people reach for an HTML widget: a YouTube video, a map, an embedded form. This release brings embeds back, from the places you name and nowhere else.

There is a new Allowed iframe hosts box on the extension's settings page. Put one host on each line:

www.youtube.com
*.vimeo.com

An embed is kept only if it loads from a host on that list. A plain entry matches that host exactly. A *. prefix matches any subdomain, so *.vimeo.com covers player.vimeo.com but not vimeo.com by itself, and you can list both if you need both.

The box starts empty, and an empty box strips every iframe exactly as it does today. Nothing changes on your forum until you decide to allow something.

Three things the setting deliberately cannot switch off. Only http and https embeds are ever kept. Script tags, event-handler attributes and javascript: links are still removed as before. And an iframe carrying its own HTML instead of a web address is always dropped, because there would be no address to check against your list.

One thing worth knowing: the checking happens in your visitors' browsers. Treat the allowlist as a guard against pasting something you did not mean to, rather than as a security boundary. Anyone who can edit this setting is already an administrator of your forum.

After updating

Run php flarum cache:clear, so the rebuilt assets are the ones your visitors get.

v1.2.1

Choose a tag to compare

@karl-bullock karl-bullock released this 13 Aug 00:50
4be96e9

Changed

  • The README now documents the settings and styling hooks in full, so the extension's page explains what it does before you install it.

Changed

  • The package details now point at this extension's own page on linkrobins.com, and list the correct PHP requirement and where to report a problem.

Nothing on your forum changes. This release exists so the information shown on Packagist matches the extension's page.

v1.2.0

Choose a tag to compare

@karl-bullock karl-bullock released this 23 Jul 22:37

What's new

Custom background color. You can now set a background color for the widget on its settings page. The widget's box takes the color you choose, and the text automatically switches to dark or light so it stays readable on both light and dark themes. Leave it blank to keep following your theme.

Edits show up on a normal refresh. After changing the widget's content or color, a normal page reload now shows the update. No more needing a hard refresh.

Also: the extension's name in the admin panel now reads "Link Robins HTML Widget" (it was showing a shortened "Link Robins HTML").

Updating

composer update linkrobins/html-widget
php flarum cache:clear

v1.1.2

Choose a tag to compare

@karl-bullock karl-bullock released this 04 Jul 19:38

Changed

  • The widget content endpoint now allows browsers to cache its response for five minutes, so the widget no longer re-fetches its content on every page view. Edits you make in the admin panel still show up within a few minutes.
  • Rendered widget content follows the Font Sizer reading-size setting if you run that extension.

Under the hood

  • Automated tests for the content endpoint and its caching contract, static analysis, CI on every change, and updated TypeScript tooling.

v1.1.1

Choose a tag to compare

@karl-bullock karl-bullock released this 31 May 00:35

Maintenance release: set package author metadata to Karl Bullock karl@linkrobins.com.

v1.1.0

Choose a tag to compare

@karl-bullock karl-bullock released this 28 May 01:09

HTML widget for fof/forum-widgets-core — v1.1.0

Security

  • Output is sanitised — the admin-supplied HTML is passed through DOMPurify (bundled into the build) before display, stripping <script> tags, event-handler attributes, javascript: URLs and unsafe elements such as <iframe>.

Changed

  • Content is loaded on demand — the widget body is fetched from a small API endpoint when the widget renders, instead of being serialised into every forum page's payload.
  • Rebuilt on fof's Widget base class (the documented widget pattern).
  • Added a proper build toolchain (webpack + TypeScript); source lives in js/src/.
  • composer.json: requires PHP ^8.3 (matches Flarum core) and pins fof/forum-widgets-core to ^2.0.0-beta.3.

⚠️ Upgrade note

The HTML body is now sanitised (previously rendered as-is). <script>, event handlers, javascript: URLs and <iframe> embeds will be stripped. If you relied on an iframe embed, let us know and a curated allowlist can be added.

i18n

  • All admin settings strings (labels, help text, and the title placeholder) are translatable.

v1.0.0

Choose a tag to compare

@karl-bullock karl-bullock released this 10 May 18:49
0b93caa