Description
frontend-app-authoring is upgrading TinyMCE from 5.10 to 7.9 in openedx/frontend-app-authoring#3245, which fixes CVE-2024-29881 and the other vulnerabilities Renovate flagged. Every other MFE that embeds TinyMCE is still on 5.10 and carries the same vulnerabilities, so they need the same bump.
The MFEs still on TinyMCE 5 are frontend-app-discussions, frontend-app-communications and frontend-app-ora. frontend-app-publisher also uses it, but it is archived and therefore out of scope.
The authoring PR is the reference implementation. It documents the v5 to v7 breaking changes that actually bite (removal of tinymce.editors, the hr and imagetools plugins going away, formatselect renamed to blocks, explicit imports for the dom model and each core plugin, and the licenseKey needed to silence the evaluation-mode warning), as well as the behavior changes that come with the upgrade (convert_unsafe_embeds, paste_data_images, highlight_on_focus, and the move to GPL-2.0-or-later). Read it before starting on each MFE.
Note that unit tests are not enough to validate this upgrade: in authoring, a duplicated TinyMCE core would have broken the editor at runtime while the suite stayed green. Each MFE needs manual verification in the browser.
Longer term we should stop duplicating this configuration in every MFE. A shared rich text editor package, as discussed in https://discuss.openedx.org/t/should-we-build-a-paragon-native-text-editor/19168, would let us bump one dependency instead of several, and once these MFEs are on frontend-base TinyMCE could be a global peer dependency so the bump is forced rather than optional. Neither is a prerequisite for this epic.
Description
frontend-app-authoring is upgrading TinyMCE from 5.10 to 7.9 in openedx/frontend-app-authoring#3245, which fixes CVE-2024-29881 and the other vulnerabilities Renovate flagged. Every other MFE that embeds TinyMCE is still on 5.10 and carries the same vulnerabilities, so they need the same bump.
The MFEs still on TinyMCE 5 are frontend-app-discussions, frontend-app-communications and frontend-app-ora. frontend-app-publisher also uses it, but it is archived and therefore out of scope.
The authoring PR is the reference implementation. It documents the v5 to v7 breaking changes that actually bite (removal of
tinymce.editors, thehrandimagetoolsplugins going away,formatselectrenamed toblocks, explicit imports for thedommodel and each core plugin, and thelicenseKeyneeded to silence the evaluation-mode warning), as well as the behavior changes that come with the upgrade (convert_unsafe_embeds,paste_data_images,highlight_on_focus, and the move to GPL-2.0-or-later). Read it before starting on each MFE.Note that unit tests are not enough to validate this upgrade: in authoring, a duplicated TinyMCE core would have broken the editor at runtime while the suite stayed green. Each MFE needs manual verification in the browser.
Longer term we should stop duplicating this configuration in every MFE. A shared rich text editor package, as discussed in https://discuss.openedx.org/t/should-we-build-a-paragon-native-text-editor/19168, would let us bump one dependency instead of several, and once these MFEs are on frontend-base TinyMCE could be a global peer dependency so the bump is forced rather than optional. Neither is a prerequisite for this epic.