Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
201 changes: 201 additions & 0 deletions dotCMS/src/main/webapp/ext/tinymcev7/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,207 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html),
and is generated by [Changie](https://github.com/miniscruff/changie).

## 7.9.3 - 2026-05-19

### Security
- Fixed media plugin `data-mce-object` injection leading to stored XSS. #TINY-14357
- Fixed stored XSS vulnerability through `mce:protected` comments. #TINY-14353
- Fixed stored XSS vulnerability through `data-mce-` prefixed `src`, `href`, `style` attributes. #TINY-14333

## 7.9.2 - 2026-02-11

### Deprecated
- The default value of `allow_html_in_comments` will change from `true` to `false` in TinyMCE 8.x. #TINY-11900

### Security
- Updated dependencies and parsing logic for enhanced content sanitization. HTML-like content in comments and certain legacy patterns are now sanitized more strictly when `xss_sanitization` is enabled (default). The Introduced `allow_html_in_comments` option provides control over comment node sanitization behavior.
#TINY-11900
- Introduced `allow_html_in_comments` option (boolean, default: `true`) to control handling of HTML-like syntax in comment nodes. This option will default to `false` in TinyMCE 8.x. #TINY-11900

## 7.9.1 - 2025-05-29

### Improved
- Update `Notices` file and minified notices. #TINY-12091

## 7.9.0 - 2025-05-15

### Added
- Added new `disc` style option for unordered lists. #TINY-12015

### Improved
- The resize cursor now points in the correct direction for each resize mode. Patch contributed by daniloff200. ##GH-10189
- If `style_formats` is empty, the button is now disabled. #TINY-12005
- Inline dialog dropdowns reposition when the dialog is dragged or the window is scrolled. #TINY-11368
- Bullet list icons were have been updated to better represent the default styles. #TINY-12014

### Changed
- The ContextFormSizeInput lock button is now centered instead of aligned to the end. #TINY-11916
- Changed the default value of `advlist_bullet_styles` option to `default,disc,circle,square`. #TINY-12083

### Fixed
- Autolink no longer overrides already existing links when autolinking. #TINY-11836
- Removed the deprecated CSS media selector `-ms-high-contrast`. #TINY-11876
- The `mceInsertContent` command no longer deletes the parent block element when an anchor is selected. #TINY-11953
- Table resizers are now visible when inline editor has a z-index property. #TINY-11981
- Tabbing inside a `figcaption` element no longer displays two text insertion carets. #TINY-11997
- Pressing Enter before a floating image no longer duplicates the image. #TINY-11676
- Editor did not scroll into viewport on receiving focus on Chrome and Safari. #TINY-12017
- Select UI elements was not properly styled on Chrome version 136. #TINY-12131

## 7.8.0 - 2025-04-09

### Added
- New subtoolbar support for context toolbars. #TINY-11748
- New `extended_mathml_attributes` and `extended_mathml_elements` options. #TINY-11756
- New `onboarding` option. #TINY-11931

### Improved
- Focus outline was misaligned with comment card border on saving an edit. #TINY-11329
- The `editor.selection.scrollIntoView()` method now pads the target scroll area with a small margin, ensuring content doesn't sit at the very edge of the viewport. #TINY-11786

### Changed
- Changed promotional text and link. #TINY-11905

### Fixed
- Setting editor height to a `pt` or `em` value was ignoring min/max height settings. #TINY-11108

## 7.7.2 - 2025-03-19

### Fixed
- Error was thrown when pressing tab in the last cell of a non-editable table. #TINY-11797
- Error was thrown when trying to use the context form API after a component was detached. #TINY-11781
- Deleting an empty block within an <li> element would move cursor to the end of the <li>. #TINY-11763
- Deleting an empty block that was between two lists would throw an Error when all three elements were nested inside a list. #TINY-11763

## 7.7.1 - 2025-03-05

### Fixed
- Skin UI content CSS was truncated when bundling, causing CSS styles to be missing. #TINY-11875
- Context forms used to disappear if their input was disabled in the `onSetup` API. #TINY-11890

## 7.7.0 - 2025-02-20

### Added
- `link_attributes_postprocess` option that allows overriding attributes of a link that would be inserted through the link dialog. #TINY-11707

### Improved
- Improved visual indication of keyboard focus in annotations that contain an image. #TINY-11596
- The type now defaults to `info` when `editor.notificationManager.open()` is used without a specified type or with an invalid one. #TINY-11661

### Changed
- Updated the `link` plugin behavior to move the cursor outside of the link when inserted or edited via the UI. Patch contributed by Philipp91. #GH-9998

### Fixed
- Keyboard navigation for size inputs in context forms. #TINY-11394
- Keyboard navigation for context form sliders. #TINY-11482
- The `insertContent` API was not replacing selected non-editable elements correctly. #TINY-11714
- Context toolbar inputs had incorrect margins. #TINY-11624
- Iframe aria text no longer suggests opening the help dialog when the help plugin is not enabled. #TINY-11672
- Preview dialog no longer opens anchor links in a new tab. #TINY-11740
- The `float` property was not properly removed on the image when converting a image into a captioned image. #TINY-11670
- Expanding selection to word didn't work inside inline editing host elements. #TINY-11304
- The `semantics` element in MathML was not properly retained when `annotation` elements were allowed. #TINY-11755
- It was possible to tab to a toolbar group that had all children disabled. #TINY-11665
- Keyboard navigation would get stuck on the 'more' toolbar button. #TINY-11762
- Toolbar groups had both a `title` attribute and a custom tooltip, causing overlapping tooltips #TINY-11768
- Toolbar text field did not render focus correctly. #TINY-11658

## 7.6.1 - 2025-01-22

### Fixed
- Text input was prevented in form elements in the contents of the editor. #TINY-11446
- Opening a notification when the toolbar is positioned at the bottom of the editor threw an error. #TINY-11498
- Table resize bars were not properly aligned for inline editors inside scrollable containers. #TINY-11215

## 7.6.0 - 2024-12-11

### Added
- It is now possible to create labeled groups in context toolbars. #TINY-11095
- New `contextsliderform` and `contextsizeinput` context form types. #TINY-11342
- New `back` function in `ContextFormApi` to go back to the previous toolbar. #TINY-11344
- New `QuickbarInsertImage` command that is executed by the `quickimage` button. #TINY-11399
- New `onSetup` function to the context form API. #TINY-11494
- New `placeholder` to the context form input field API. #TINY-11459
- New `disabled` option to restore the previous `readonly` mode behavior, allowing the editor to be displayed in a disabled state. #TINY-11488

### Improved
- Base64 data was not properly decoded due to unhandled URL-encoded characters. #TINY-9548
- The `latin` list style type is now recognized as an alias for the `alpha` list style type. #TINY-11515

### Fixed
- Image selection was removed when calling `editor.nodeChanged()` while having focus inside the editor UI. #TINY-11437
- Tooltip would not show for group toolbar button. #TINY-11391
- Changing the table row type when a `contenteditable=false` cell was selected would not work as expected. #TINY-11383
- The `samp` format was being applied as a `block` level format, instead of an `inline` format. #TINY-11390
- Removed title attribute from dialog tree elements as they already have a tooltip. #TINY-11470
- Fixed CSS bundling for skin UI content CSS. #TINY-11558
- Fixed incorrect resource keys for CSS bundling JS files. #TINY-11558

## 7.5.0 - 2024-11-06

### Added
- Added support for using raw CSS in the list of possible colours, using the `color_map_raw` property. #GH-9788

### Improved
- Improved color picker aria support. #TINY-11291

### Fixed
- Autocompleter would not activate after applying an inline format like font size in some cases. #TINY-11273
- The `toolbar-sticky-offset` would still be applied after entering fullscreen mode. #TINY-11137
- Text and background color toolbar buttons would not be fully greyed out in readonly mode. #TINY-11313
- Closing a nested modal dialog would lose focus from the editor. #TINY-11153
- Inability to type '{' character on German keyboard layouts. #TINY-11395

## 7.4.1 - 2024-10-10

### Fixed
- Invalid HTML elements within SVG elements were not removed. #TINY-11332

## 7.4.0 - 2024-10-09

### Added
- New `context` property for all ui components. This allows buttons and menu items to be enabled or disabled based on whether their context matches a given predicate; status updates are checked on `init`, `NodeChange`, and `SwitchMode` events. #TINY-11211
- Tree component now allows the addition of a custom icon. #TINY-11131
- Added focus function to view button api. #TINY-11122
- New option `allow_mathml_annotation_encodings` to opt-in to keep math annotations with specific encodings. #TINY-11166
- Added global `color-active` LESS variable for use in editor skins. #TINY-11266

### Improved
- In read-only mode the editor now allows normal cursor movement and block element selection, including video playback. #TINY-11264
- Pasting a table now places the cursor after the table instead of into the last cell. #TINY-11082
- Dialog list dropdown menus now close when the browser window resizes. #TINY-11123

### Fixed
- Mouse hover on partially visible dialog collection elements no longer scrolls. #TINY-9915
- Caret would unexpectedly shift to the non-editable table row above when pressing Enter. #TINY-11077
- Deleting a selection in a list element would sometimes prevent the `input` event from being dispatched. #TINY-11100
- Placing the cursor after a table with a br after it would misplace added newlines before the table instead of after. #TINY-11110
- Sidebar could not be toggled until the skin was loaded. #TINY-11155
- The image dialog lost focus after closing an image upload error alert. #TINY-11159
- Copying tables to the clipboard did not correctly separate cells and rows for the "text/plain" MIME type. #TINY-10847
- The editor resize handle was incorrectly rendered when all components were removed from the status bar. #TINY-11257

## 7.3.0 - 2024-08-07

### Added
- Colorpicker number input fields now show an error tooltip and error icon when invalid text has been entered. #TINY-10799
- New `format-code` icon. #TINY-11018

### Improved
- When a full document was loaded as editor content the head elements were added to the body. #TINY-11053

### Fixed
- Unnecessary nbsp entities were inserted when typing at the edges of inline elements. #TINY-10854
- Fixed JavaScript error when inserting a table using the context menu by adjusting the event order in `renderInsertTableMenuItem`. #TINY-6887
- Notifications didn't position and resize properly when resizing the editor or toggling views. #TINY-10894
- The pattern commands would execute even if the command was not enabled. #TINY-10994
- Split button popups were incorrectly positioned when switching to fullscreen mode if the editor was inside a scrollable container. #TINY-10973
- Sequential html comments would in some cases generate unwanted elements. #TINY-10955
- The listbox component had a fixed width and was not a responsive ui element. #TINY-10884
- Prevent default mousedown on toolbar buttons was causing misplaced focus bugs. #TINY-10638
- Attempting to use focus commands on an editor where the cursor had last been in certain contentEditable="true" elements would fail. #TINY-11085
- Colorpicker's hex-based input field showed the wrong validation error message. #TINY-11115

## 7.2.1 - 2024-07-03

### Fixed
Expand Down
2 changes: 1 addition & 1 deletion dotCMS/src/main/webapp/ext/tinymcev7/composer.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "tinymce/tinymce",
"version": "7.2.1",
"version": "7.9.3",
"description": "Web based JavaScript HTML WYSIWYG editor control.",
"license": [
"GPL-2.0-or-later"
Expand Down
Loading
Loading