Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
93 commits
Select commit Hold shift + click to select a range
3609671
Merge pull request #67 from contentstack/RT-360
shreya-kamble Jan 10, 2025
6bf6474
fix: convert numeric width to string for images
Jayesh2812 Jan 10, 2025
591464f
Merge pull request #68 from contentstack/RT-383
Jayesh2812 Jan 10, 2025
10c3a0f
Update package.json version
Jayesh2812 Jan 10, 2025
50dff96
fix: ecode social-embeds and embeds src urls
shreya-kamble Jan 16, 2025
9daa205
chore: readme update
shreya-kamble Jan 16, 2025
d4f28d1
Merge pull request #72 from contentstack/RT-360
shreya-kamble Jan 16, 2025
e46ee03
fix: escape html entities in attr values
shreya-kamble Jan 21, 2025
500508f
Merge pull request #75 from contentstack/RT-360
shreya-kamble Jan 21, 2025
16d29e6
feat: handle invalid attr key-values
shreya-kamble Jan 22, 2025
1b83dcd
Merge pull request #76 from contentstack/RT-360
shreya-kamble Jan 22, 2025
1d02984
Merge branch 'master' into development
Aravind-Kumar-cstk Jan 23, 2025
f4a66c2
Update LICENSE
shreya-kamble Jan 23, 2025
db47a9e
Merge pull request #69 from contentstack/development
shreya-kamble Jan 23, 2025
4264c10
fix: retain empty strings value for alt attr for img and asset while …
shreya-kamble Mar 6, 2025
a9c3756
chore: remove unnecessary imports
shreya-kamble Mar 6, 2025
5eb814c
feat: dynamically allow attribute values to be empty if elemnt and at…
shreya-kamble Mar 10, 2025
7b61a9c
chore: code optimisation
shreya-kamble Mar 13, 2025
78b8f26
feat: hr as a tag not data type
shreya-kamble Mar 19, 2025
c520ddc
fix: optimise conditions added
shreya-kamble Mar 19, 2025
883020b
fix: optimise conditions added
shreya-kamble Mar 19, 2025
2979273
Merge pull request #80 from contentstack/RT-411
shreya-kamble Mar 19, 2025
66c0ecc
Merge pull request #81 from contentstack/RT-268
shreya-kamble Mar 19, 2025
549d514
Update package.json
shreya-kamble Mar 19, 2025
8c071ce
Merge pull request #82 from contentstack/dev
shreya-kamble Mar 25, 2025
24a36c9
fix: br tags added as per no.of \n
shreya-kamble Apr 7, 2025
08fa679
chore: package version upgrade
shreya-kamble Apr 7, 2025
d0f8038
Merge pull request #84 from contentstack/RT-483
shreya-kamble Apr 9, 2025
d2ddd73
fix: headings format returned in markdown was not as expected
shreya-kamble Apr 9, 2025
cc732e5
sca-scan.yml
Aravind-Kumar-cstk Apr 15, 2025
904b869
policy-scan.yml
Aravind-Kumar-cstk Apr 15, 2025
d5920de
issues-jira.yml
Aravind-Kumar-cstk Apr 15, 2025
30c2d3c
Delete jira.yml
Aravind-Kumar-cstk Apr 15, 2025
c50e04b
Delete sast-scan.yml
Aravind-Kumar-cstk Apr 15, 2025
b1a00ef
codeql-analysis.yml
Aravind-Kumar-cstk Apr 15, 2025
9a5a865
Updated codeowners
Aravind-Kumar-cstk Apr 15, 2025
6f65b90
policy-scan.yml
Aravind-Kumar-cstk Apr 16, 2025
debd447
issues-jira.yml
Aravind-Kumar-cstk Apr 16, 2025
11d7945
codeql-analysis.yml
Aravind-Kumar-cstk Apr 16, 2025
addb625
Updated codeowners
Aravind-Kumar-cstk Apr 16, 2025
dd71d4d
policy-scan.yml
Aravind-Kumar-cstk Apr 23, 2025
a730a50
policy-scan.yml
Aravind-Kumar-cstk May 5, 2025
a92d253
issues-jira.yml
Aravind-Kumar-cstk May 5, 2025
e295b6b
secrets-scan.yml
Aravind-Kumar-cstk May 5, 2025
1afa4c7
Updated codeowners
Aravind-Kumar-cstk May 5, 2025
407773e
talismanrc file updated
Aravind-Kumar-cstk May 5, 2025
b8f20a5
Titel attr added on A element
manojcon May 13, 2025
98f33c4
resolve PR comment
manojcon May 13, 2025
c1b28f1
Merge pull request #85 from contentstack/RT-488
shreya-kamble May 14, 2025
1282aff
Merge pull request #86 from contentstack/RT-501
manojcon May 15, 2025
281e231
feat: preserve empty blocks while converting to html
shreya-kamble May 21, 2025
1e902ed
Merge pull request #87 from contentstack/RT-496
shreya-kamble May 21, 2025
6037a82
Update package.json
shreya-kamble May 21, 2025
ae88512
fix: remove invisible psace added in json text in case of nbsp
shreya-kamble May 22, 2025
42d81a2
Merge branch 'dev' into RT-496
shreya-kamble May 22, 2025
e636c88
Merge pull request #89 from contentstack/RT-496
shreya-kamble May 22, 2025
1c21b04
chore: add skipchecks in talismanrc
shreya-kamble May 22, 2025
302fad6
Merge pull request #88 from contentstack/dev
shreya-kamble May 22, 2025
8cda183
fix: rt-531
shreya-kamble Jun 12, 2025
f12235e
Update package.json
shreya-kamble Jun 12, 2025
ee07e90
Merge pull request #90 from contentstack/RT-531
shreya-kamble Jul 8, 2025
af9212c
[RT-611][bug] Moved the constants to separate file and used them to c…
naithanishant Aug 19, 2025
ed3abda
[RT-611][bug] Small fixes
naithanishant Aug 19, 2025
8d9d71c
[RT-611][bug] Test cases fix
naithanishant Aug 19, 2025
7387834
[RT-611][bug] Security Scan
naithanishant Aug 19, 2025
9fdf694
[RT-611][bug] Security Scan
naithanishant Aug 19, 2025
03d0aee
Merge pull request #91 from contentstack/nn-bug-RT-611
naithanishant Aug 20, 2025
7c38c53
[RT-611][bug] Version bump
naithanishant Aug 20, 2025
8bfbadb
Merge pull request #92 from contentstack/development
naithanishant Aug 21, 2025
af490af
Delete secrets-scan.yml
Aravind-Kumar-cstk Sep 8, 2025
0be0338
Updated codeowners
Aravind-Kumar-cstk Sep 8, 2025
eb158e8
sca-scan.yml
Aravind-Kumar-cstk Dec 24, 2025
8758234
policy-scan.yml
Aravind-Kumar-cstk Dec 24, 2025
91acb10
issues-jira.yml
Aravind-Kumar-cstk Dec 24, 2025
22c86df
Updated codeowners
Aravind-Kumar-cstk Dec 24, 2025
3a3ab9d
Update CODEOWNERS
Aravind-Kumar-cstk Dec 24, 2025
e3efc04
feat: indent support
shreya-kamble Jan 23, 2026
ecca7c9
chore: update licence
shreya-kamble Jan 23, 2026
c09917b
Merge pull request #97 from contentstack/RT-659-1
shreya-kamble Jan 23, 2026
d957b02
Update package.json
shreya-kamble Jan 28, 2026
662d74d
Merge pull request #98 from contentstack/RT-v3.0.5
shreya-kamble Jan 28, 2026
945d23c
Update sca-scan.yml
dhavaljain999 Mar 3, 2026
3010c9b
chore(deps): security fixes and toolchain updates [EXP-406]
harshalpatel91 May 6, 2026
8b5d48b
Update package.json
harshalpatel91 May 18, 2026
4ecb816
chore: sanity and version upgrade
shreya-kamble May 18, 2026
a4ddc9c
Merge pull request #99 from contentstack/EXP-406
shreya-kamble May 18, 2026
e2ea91b
chore: ci rules
shreya-kamble May 18, 2026
7225610
Merge branch 'master' into EXP-406
shreya-kamble May 18, 2026
4dfe48b
Merge pull request #102 from contentstack/EXP-406
shreya-kamble May 18, 2026
fb107ca
fix: jsdom overrides
shreya-kamble May 18, 2026
c839741
Merge branch 'master' into EXP-406
shreya-kamble May 18, 2026
4e01641
Merge pull request #103 from contentstack/EXP-406
shreya-kamble May 18, 2026
4cb73b6
fix: skip text wrappers when mark value is falsy
SachinAryaMckinsey Jun 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 31 additions & 0 deletions .github/workflows/issues-jira.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
name: Create Jira Ticket for Github Issue

on:
issues:
types: [opened]

jobs:
issue-jira:
runs-on: ubuntu-latest
steps:

- name: Login to Jira
uses: atlassian/gajira-login@master
env:
JIRA_BASE_URL: ${{ secrets.JIRA_BASE_URL }}
JIRA_USER_EMAIL: ${{ secrets.JIRA_USER_EMAIL }}
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}

- name: Create Jira Issue
id: create_jira
uses: atlassian/gajira-create@master
with:
project: ${{ secrets.JIRA_PROJECT }}
issuetype: ${{ secrets.JIRA_ISSUE_TYPE }}
summary: Github | Issue | ${{ github.event.repository.name }} | ${{ github.event.issue.title }}
description: |
*GitHub Issue:* ${{ github.event.issue.html_url }}

*Description:*
${{ github.event.issue.body }}
fields: "${{ secrets.ISSUES_JIRA_FIELDS }}"
33 changes: 0 additions & 33 deletions .github/workflows/jira.yml

This file was deleted.

16 changes: 9 additions & 7 deletions .github/workflows/npm-publish-github-packages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,10 +11,11 @@ jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 16
node-version: 22 # ← was 16
cache: 'npm'
- run: npm ci
- run: npm test

Expand All @@ -25,12 +26,13 @@ jobs:
contents: read
packages: write
steps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 16
node-version: 22 # ← was 16
registry-url: https://npm.pkg.github.com/
cache: 'npm'
- run: npm ci
- run: npm publish
env:
NODE_AUTH_TOKEN: ${{secrets.GITHUB_TOKEN}}
NODE_AUTH_TOKEN: ${{secrets.GITHUB_TOKEN}}
14 changes: 8 additions & 6 deletions .github/workflows/npm-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,22 +11,24 @@ jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 16
node-version: 22
cache: 'npm'
- run: npm ci
- run: npm test

publish-npm:
needs: build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/setup-node@v3
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 16
node-version: 22
registry-url: https://registry.npmjs.org/
cache: 'npm'
- run: npm ci
- run: npm publish
env:
Expand Down
46 changes: 46 additions & 0 deletions .github/workflows/policy-scan.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
name: Checks the security policy and configurations
on:
pull_request:
types: [opened, synchronize, reopened]
jobs:
security-policy:
if: github.event.repository.visibility == 'public'
runs-on: ubuntu-latest
defaults:
run:
shell: bash
steps:
- uses: actions/checkout@master
- name: Checks for SECURITY.md policy file
run: |
if ! [[ -f "SECURITY.md" || -f ".github/SECURITY.md" ]]; then exit 1; fi
security-license:
if: github.event.repository.visibility == 'public'
runs-on: ubuntu-latest
defaults:
run:
shell: bash
steps:
- uses: actions/checkout@master
- name: Checks for License file
run: |
expected_license_files=("LICENSE" "LICENSE.txt" "LICENSE.md" "License.txt")
license_file_found=false
current_year=$(date +"%Y")

for license_file in "${expected_license_files[@]}"; do
if [ -f "$license_file" ]; then
license_file_found=true
# check the license file for the current year, if not exists, exit with error
if ! grep -q "$current_year" "$license_file"; then
echo "License file $license_file does not contain the current year."
exit 2
fi
break
fi
done

if [ "$license_file_found" = false ]; then
echo "No license file found. Please add a license file to the repository."
exit 1
fi
11 changes: 0 additions & 11 deletions .github/workflows/sast-scan.yml

This file was deleted.

3 changes: 3 additions & 0 deletions .github/workflows/sca-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,6 @@ jobs:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
with:
args: --all-projects --fail-on=all
json: true
continue-on-error: true
- uses: contentstack/sca-policy@main
12 changes: 12 additions & 0 deletions .talismanrc
Original file line number Diff line number Diff line change
@@ -1,4 +1,7 @@
fileignoreconfig:
- filename: .github/workflows/secrets-scan.yml
ignore_detectors:
- filecontent
- filename: README.md
checksum: 4bffa07e1e88d50a311464c9f90ff92bcba7fe434be4d9374bcd49bf76b1e6a8
- filename: coverage/lcov-report/base.css
Expand All @@ -21,3 +24,12 @@ fileignoreconfig:
checksum: 3d014702628ad538065c970d988a695af003c61663596a8f6b9267b4e57ef6ea
- filename: test/expectedJson.json
checksum: 9979f84be3e5aa27f24381a0c49e0e6696388d19615c4f3b09082780968236ee
- filename: README.md
checksum: cccb3cd93c499acc87593eca5cc032e256c11cf530d4de67ece09e57fc430215
- filename: test/expectedJson.ts
checksum: a1966b0b3993c8e3a0e9e45de49204e7788ba74ba0089a8a6b6eba0729f990bd
- filename: package-lock.json
checksum: 96da2dcdb517a744b09062fad7fbe38f49e4efe5535a3e9e65a94805e7e4808c
- filename: src/toRedactor.tsx
checksum: c6792b5b19cf89024ab33333a77d22af0375d4976c2fc64dae1d2f5971493397
version: "1.0"
12 changes: 11 additions & 1 deletion CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1 +1,11 @@
* @contentstack/security-admin
* @contentstack/venus-pr-reviewers

.github/workflows/sca-scan.yml @contentstack/security-admin

.github/workflows/codeql-anaylsis.yml @contentstack/security-admin

**/.snyk @contentstack/security-admin

.github/workflows/policy-scan.yml @contentstack/security-admin

.github/workflows/issues-jira.yml @contentstack/security-admin
2 changes: 1 addition & 1 deletion LICENSE
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
MIT License

Copyright (c) 2023-2024 Contentstack
Copyright (c) 2021-2026 Contentstack

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
Expand Down
68 changes: 68 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -161,6 +161,28 @@ On the other hand, the `customTextWrapper` parser function provides the followin
- `child`: The HTML string that specifies the child element
- `value`: The value passed against the child element

___

`allowedEmptyAttributes`

- Type: `object`
- Default: `{ img: ['alt'], reference: ['alt'] }`

Specifies which empty attributes should be retained for specific HTML elements during the jsonToHtml conversion.
By default, the converter preserves the alt attribute for <img> and reference (asset) elements, even when their values are empty.
This is particularly useful for ensuring semantic correctness and accessibility.

Use this option when you want to retain specific attributes with empty values during the conversion process.

___

`addNbspForEmptyBlocks`

- Type: `boolean`
- Default:`false`

When set to true, this option adds a non-breaking space (nbsp;) to empty blocks during the jsonToHtml conversion. This helps maintain the visual structure of the HTML output—especially useful for preserving spacing in editable content or content editors.

You can use the following customized JSON RTE Serializer code to convert your JSON RTE field data into HTML format.

```javascript
Expand Down Expand Up @@ -189,6 +211,16 @@ const jsonValue = {
},
],
},
{
"type": "p",
"uid": "28c837c127504d3c85b9cb6d7099cb0b",
"attrs": {},
"children": [
{
"text": ""
}
]
},
{
type: "p",
attrs: {},
Expand All @@ -215,6 +247,11 @@ const htmlValue = jsonToHtml(
return `<color data-color="${value}">${child}</color>`;
},
},
allowedEmptyAttributes : {
"p": ["dir"],
"img" : ["width"]
},
addNbspForEmptyBlocks : true
}
);

Expand Down Expand Up @@ -356,12 +393,43 @@ The resulting JSON-formatted data will look as follows:

## Automatic Conversion

> **_Note_**: `src` url's provided for social-embeds and embed items will by default be <a href="https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/encodeURI">uri encoded</a>.

By default, the JSON Rich Text Editor field supports limited HTML tags within the editor. Due to this, the JSON RTE Serializer tool is not able to recognize each and every standard HTML tag.

To help the JSON RTE Serializer recognize and process additional tags that are commonly used across HTML, you can use the automatic conversion option. When using this option, you need to pass the `allowNonStandardTags: true` parameter within the `jsonToHtml` or `htmlToJson` method to manipulate the working of the JSON RTE Serializer package as per your requirements. When you pass this parameter, it customizes your JSON RTE Serializer code to allow the support for all standard HTML-recognized tags or element types in the JSON Rich Text Editor field.

### Convert JSON to HTML

#### HTML Attribute Name and Value Sanitization


This project ensures that HTML attributes are properly validated and sanitized according to the W3C HTML specification. It validates attribute names based on the HTML standards and sanitizes attribute values to ensure correct rendering and security, particularly against cross-site scripting (XSS) vulnerabilities.

#### Attribute Name Guidelines

All HTML attribute names must conform to the [W3C HTML specification](https://www.w3.org/TR/2012/WD-html-markup-20120329/syntax.html#attribute-name). These guidelines specify the following rules:

- **Printable ASCII Characters:** Attribute names must consist only of printable ASCII characters.
- **Case-Insensitive:** Attribute names are case-insensitive, but lowercase is preferred for consistency.
- **No Special Characters:** Attribute names cannot contain spaces or special characters such as `=`, `>`, `<`, `"`, etc.
- **Allowed Attributes:** Attributes such as `xmlns`, `aria-*`, `data-*`, and others defined by HTML5 standards are allowed and must follow specific rules.

##### Important Note:
If an attribute name does not conform to these rules, the attribute will be **dropped** from the element.

#### Attribute Value Guidelines

The values of HTML attributes are sanitized to ensure proper rendering and to mitigate security risks, such as Cross-Site Scripting (XSS). This sanitization process involves replacing HTML entities (like `&lt;`, `&gt;`, `&amp;`, etc.) with their corresponding characters and removing any invalid or unsafe characters.

Here are some common HTML entities and their replacements:

- `&lt;` → `<`
- `&gt;` → `>`
- `&amp;` → `&`


<hr>
You can pass the `allowNonStandardTags: true` parameter within the `jsonToHtml` method to allow the JSON RTE Serializer tool to recognize standard HTML tags or element types and convert them into JSON format.

You can use the following customized JSON RTE Serializer code to convert your JSON RTE field data into HTML format.
Expand Down
7 changes: 4 additions & 3 deletions jest.config.js
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
module.exports = {
preset: 'ts-jest',
testEnvironment: 'jsdom',
testResultsProcessor: "./node_modules/jest-html-reporter"
preset: "ts-jest",
testEnvironment: "jsdom",
setupFiles: ["<rootDir>/jest.setup.js"],
testResultsProcessor: "./node_modules/jest-html-reporter",
};
4 changes: 4 additions & 0 deletions jest.setup.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
const { TextDecoder, TextEncoder } = require("util");

globalThis.TextEncoder = TextEncoder;
globalThis.TextDecoder = TextDecoder;
Loading