Serves nodes of the unrestricted_page content type as the raw contents of their field_markup field, with no theme layer at all.
For users with edit permission, also injects the admin toolbar and the contextual links and tabs so that you can still normally interact with the page.
Security
The field value is emitted unescaped. Anyone who can edit an
unrestricted_page node can inject arbitrary HTML, CSS and JavaScript into the
site's own origin - which means session-stealing XSS and full defacement.
Treat the "create/edit unrestricted_page content" permissions as equivalent to `administer site configuration` and grant them only to trusted roles.
Supporting organizations:
Original requirement and paid development time
Technical expertise
Project information
- Project categories: Content editing experience
9 sites report using this module
- Created by alemadlei on , updated
Stable releases for this project are covered by the security advisory policy.
There are currently no supported stable releases.
Releases
1.0.0-rc2
released 4 September 2026
Works with Drupal: >=10
New feature and compatiblity updates
Install:
