Releases: linkrobins/html-widget
Release list
v1.3.0
Embeds are back, for the hosts you choose
Version 1.1.0 started sanitising the widget's HTML, and that stripped every <iframe> along with it. It closed a real hole, but it also took away the main reason people reach for an HTML widget: a YouTube video, a map, an embedded form. This release brings embeds back, from the places you name and nowhere else.
There is a new Allowed iframe hosts box on the extension's settings page. Put one host on each line:
www.youtube.com
*.vimeo.com
An embed is kept only if it loads from a host on that list. A plain entry matches that host exactly. A *. prefix matches any subdomain, so *.vimeo.com covers player.vimeo.com but not vimeo.com by itself, and you can list both if you need both.
The box starts empty, and an empty box strips every iframe exactly as it does today. Nothing changes on your forum until you decide to allow something.
Three things the setting deliberately cannot switch off. Only http and https embeds are ever kept. Script tags, event-handler attributes and javascript: links are still removed as before. And an iframe carrying its own HTML instead of a web address is always dropped, because there would be no address to check against your list.
One thing worth knowing: the checking happens in your visitors' browsers. Treat the allowlist as a guard against pasting something you did not mean to, rather than as a security boundary. Anyone who can edit this setting is already an administrator of your forum.
After updating
Run php flarum cache:clear, so the rebuilt assets are the ones your visitors get.
v1.2.1
Changed
- The README now documents the settings and styling hooks in full, so the extension's page explains what it does before you install it.
Changed
- The package details now point at this extension's own page on linkrobins.com, and list the correct PHP requirement and where to report a problem.
Nothing on your forum changes. This release exists so the information shown on Packagist matches the extension's page.
v1.2.0
What's new
Custom background color. You can now set a background color for the widget on its settings page. The widget's box takes the color you choose, and the text automatically switches to dark or light so it stays readable on both light and dark themes. Leave it blank to keep following your theme.
Edits show up on a normal refresh. After changing the widget's content or color, a normal page reload now shows the update. No more needing a hard refresh.
Also: the extension's name in the admin panel now reads "Link Robins HTML Widget" (it was showing a shortened "Link Robins HTML").
Updating
composer update linkrobins/html-widget
php flarum cache:clear
v1.1.2
Changed
- The widget content endpoint now allows browsers to cache its response for five minutes, so the widget no longer re-fetches its content on every page view. Edits you make in the admin panel still show up within a few minutes.
- Rendered widget content follows the Font Sizer reading-size setting if you run that extension.
Under the hood
- Automated tests for the content endpoint and its caching contract, static analysis, CI on every change, and updated TypeScript tooling.
v1.1.1
Maintenance release: set package author metadata to Karl Bullock karl@linkrobins.com.
v1.1.0
HTML widget for fof/forum-widgets-core — v1.1.0
Security
- Output is sanitised — the admin-supplied HTML is passed through DOMPurify (bundled into the build) before display, stripping
<script>tags, event-handler attributes,javascript:URLs and unsafe elements such as<iframe>.
Changed
- Content is loaded on demand — the widget body is fetched from a small API endpoint when the widget renders, instead of being serialised into every forum page's payload.
- Rebuilt on fof's
Widgetbase class (the documented widget pattern). - Added a proper build toolchain (webpack + TypeScript); source lives in
js/src/. composer.json: requires PHP^8.3(matches Flarum core) and pinsfof/forum-widgets-coreto^2.0.0-beta.3.
⚠️ Upgrade note
The HTML body is now sanitised (previously rendered as-is). <script>, event handlers, javascript: URLs and <iframe> embeds will be stripped. If you relied on an iframe embed, let us know and a curated allowlist can be added.
i18n
- All admin settings strings (labels, help text, and the title placeholder) are translatable.
v1.0.0
Full Changelog: https://github.com/linkrobins/html-widget/commits/v1.0.0