Change record status: 
Project: 
Introduced in branch: 
1.x
Introduced in version: 
1.0.0-rc1
Description: 

What?

A number of ComponentSource plugins does not have a native explicit input UX: SDCS & code components in Canvas itself, potentially more in contrib in the future (because this is not yet a public API!).

They use the auto-generated input UX powered by field widgets, based on JSON Schema descriptions of component props.

Before
These relied on the value property from text based items, even when allowing HTML, which would cause double-escaping when rendered.
After
These now rely on the processed computed property which handles HTML filtering.

Why?

This is important for many reasons:

  • front-end developers: they had to use |raw twig filter for avoiding the double-escaping, which could trigger vulnerabilities when those components were used outside of Canvas if text format filters were misconfigured.
  • recipes/site templates developers: if they had exported Components' configuration before this fix landed, they would need to re-export after running the update path.
Impacts: 
Themers
Site templates, recipes and distribution developers