Skip to main content
New Idea

HTML In Articles for Admins

Related products:None
  • November 25, 2022
  • 7 replies
  • 84 views
security_lion
Jasper
Paul_
revote
JeppePeppe
+3
  • security_lion
    security_lion
  • Jasper
    Jasper
  • Paul_
    Paul_
  • revote
    revote
  • JeppePeppe
    JeppePeppe
  • Mattie K
    Mattie K
  • Stacia_TMBC
  • Eva
    Eva

Mattie K
  • Contributor ⭐️⭐️
  • 6 replies

We’re working on launching the Product Updates feature and have run into a series of issues with the current scope of the text editor functionality. Many of the answers found here addressed some of our questions and concerns (I love that about this community!), but while many points are on a roadmap somewhere (eg. attachments), there is an important one that as I read the answers to, only made me more curious.

The text editor itself is frankly very limited for Product Updates. At first when our team saw the <> (Source) function we assumed it would be fine and we could easily find workarounds using html and css. That… has not been that case as has been addressed in many a topic here, and all of the answers that I’ve seen regarding the deletion of any html beyond the very basic tags has been that it’s a security issue. I just… have a question about that. We’re very big on security over here, but would it not be better to simply make the ability to touch source code extremely limited based on permissions? We can give the permission to upload files, so can we do this with touching the html/css? In theory this should be a risk assumed by the client, in part mitigated by developing the source feature in a way that prevents injecting anything like js. 

If it’s limited to an admin and only accessible in the control environment, would it not be a better user experience to allow for a wider range of styling and formatting for the client through opening up the Source feature, with the burden of security/functionality being on the client as it is with anything else that we customize? If there’s a worry of too many folks having it, would there ever be a way to allow the inSided team to grant that access to specific users rather than even having it fall under a role? (eg: we have a vendor that gives ONE particular super user for our CRM special access to highly sensitive features even though we have multiple super users, those special permissions are all controlled by the vendor.)

 

This has been a big pain point for our team as they’re used to being able to bring in someone skilled with html/css to work on emails and even landing pages within our current CRM. That’s a risk that we (and all of their many clients) take on and permissions are heavily limited, which made me curious about the answers around security concerns. Of course, I’m not a cyber security specialist, which is why I’m looking for more details!! 

7 replies

Blastoise186
Forum|alt.badge.img
  • Helper ⭐️⭐️⭐️
  • 536 replies
  • November 25, 2022

Hey, welcome to inSpired!

I’m one of the regulars who helps out here and conveniently, I’m a cyber security guy myself.

Sorry to be a bit difficult, but due to the nature of this one, I think it might be best for @tom.shaddock to pick this one up. You might also find it easier to ping an email to support@insided.com as I don’t think it’s that easy to talk about publicly for security reasons.

If you think you’ve found a security bug, definitely let inSided know! support@insided.com is the best route for it and someone will get back to you ASAP.


revote
Forum|alt.badge.img+2
  • VIP ⭐️⭐️⭐️⭐️⭐️
  • 790 replies
  • November 25, 2022

Yeah, this is something I have asked as well. There are situations where, as a admin, you want to add some html to the post. This should be possible for the admins, no one else.


olimarrio
Forum|alt.badge.img+4
  • Gainsight Employee ⭐️
  • 402 replies
  • December 1, 2022

Hi @Mattie K 👋,

You raise some very good points which I very much agree with. In the past, our security team have pushed back on this but if we can make this functionality role based, then this would mitigate the risk (or at least put the onus on the client like you stated). 

It’s not currently possible with the existing functionality but I’ll edit the title of this post slightly and convert this question to an idea so that this can be voted on.


Cristina
Forum|alt.badge.img+1
  • Helper ⭐️⭐️⭐️
  • 530 replies
  • December 1, 2022

Hi all, thank you for this suggestion and all the input! It is an interesting approach and I will take it to our engineers and security team to review it. In the meantime, will set the status to open to collect further votes and insights. 


Cristina
Forum|alt.badge.img+1
  • Helper ⭐️⭐️⭐️
  • 530 replies
  • December 1, 2022
NewOpen

Mattie K
  • Author
  • Contributor ⭐️⭐️
  • 6 replies
  • December 6, 2022

Hi @olimarrio Thank you for picking this up!.Looking forward to seeing where it goes, and always appreciative of the timely communication/action!


JeppePeppe
  • Helper ⭐️⭐️
  • 52 replies
  • December 7, 2022

This would be a huge improvement. We’ve made some workarounds in Custom-CSS to style spoilers as buttons for example. But this would really help! I hope we can get this to work 😊


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings