v1.1.0
HTML widget for fof/forum-widgets-core — v1.1.0
Security
- Output is sanitised — the admin-supplied HTML is passed through DOMPurify (bundled into the build) before display, stripping
<script>tags, event-handler attributes,javascript:URLs and unsafe elements such as<iframe>.
Changed
- Content is loaded on demand — the widget body is fetched from a small API endpoint when the widget renders, instead of being serialised into every forum page's payload.
- Rebuilt on fof's
Widgetbase class (the documented widget pattern). - Added a proper build toolchain (webpack + TypeScript); source lives in
js/src/. composer.json: requires PHP^8.3(matches Flarum core) and pinsfof/forum-widgets-coreto^2.0.0-beta.3.
⚠️ Upgrade note
The HTML body is now sanitised (previously rendered as-is). <script>, event handlers, javascript: URLs and <iframe> embeds will be stripped. If you relied on an iframe embed, let us know and a curated allowlist can be added.
i18n
- All admin settings strings (labels, help text, and the title placeholder) are translatable.