Skip to content

Upgrade TinyMCE to v7 in all MFEs that use it #571

Description

@arbrandes

Description

frontend-app-authoring is upgrading TinyMCE from 5.10 to 7.9 in openedx/frontend-app-authoring#3245, which fixes CVE-2024-29881 and the other vulnerabilities Renovate flagged. Every other MFE that embeds TinyMCE is still on 5.10 and carries the same vulnerabilities, so they need the same bump.

The MFEs still on TinyMCE 5 are frontend-app-discussions, frontend-app-communications and frontend-app-ora. frontend-app-publisher also uses it, but it is archived and therefore out of scope.

The authoring PR is the reference implementation. It documents the v5 to v7 breaking changes that actually bite (removal of tinymce.editors, the hr and imagetools plugins going away, formatselect renamed to blocks, explicit imports for the dom model and each core plugin, and the licenseKey needed to silence the evaluation-mode warning), as well as the behavior changes that come with the upgrade (convert_unsafe_embeds, paste_data_images, highlight_on_focus, and the move to GPL-2.0-or-later). Read it before starting on each MFE.

Note that unit tests are not enough to validate this upgrade: in authoring, a duplicated TinyMCE core would have broken the editor at runtime while the suite stayed green. Each MFE needs manual verification in the browser.

Longer term we should stop duplicating this configuration in every MFE. A shared rich text editor package, as discussed in https://discuss.openedx.org/t/should-we-build-a-paragon-native-text-editor/19168, would let us bump one dependency instead of several, and once these MFEs are on frontend-base TinyMCE could be a global peer dependency so the bump is forced rather than optional. Neither is a prerequisite for this epic.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

maintenanceRoutine upkeep necessary for the health of the platformsecurityRelates to improving to the security posture of the platform

Type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions