You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The following premium plugin updates were released alongside {productname} {release-version}.
31
31
32
+
=== TinyMCE AI
33
+
34
+
The {productname} {release-version} release includes an accompanying release of the **TinyMCE AI** premium plugin.
35
+
36
+
**TinyMCE AI** includes the following fix.
37
+
38
+
==== AI Review suggestion cards now stay available when you close and reopen the review sidebar while suggestions are still loading
39
+
// #TINY-14197
40
+
41
+
Previously, closing the TinyMCE AI Review sidebar immediately after starting a review and then reopening it after the AI finished generating suggestions would reset the sidebar state. The suggestion cards associated with the review were not displayed, and instead the list of available reviews appeared alongside the preview. This prevented the generated suggestions from being actioned.
42
+
43
+
In {productname} {release-version}, the sidebar state is now correctly preserved when the sidebar is closed and reopened during or after suggestion generation. The review suggestion cards remain visible and actionable, even if the sidebar was closed while the AI was still streaming results.
44
+
45
+
For information on the **TinyMCE AI** plugin, see: xref:tinymceai.adoc[TinyMCE AI].
46
+
32
47
=== <Premium plugin name 1> <Premium plugin name 1 version>
33
48
34
49
The {productname} {release-version} release includes an accompanying release of the **<Premium plugin name 1>** premium plugin.
@@ -41,6 +56,101 @@ The {productname} {release-version} release includes an accompanying release of
41
56
42
57
For information on the **<Premium plugin name 1>** plugin, see: xref:<plugincode>.adoc[<Premium plugin name 1>].
43
58
59
+
=== TinyMCE AI
60
+
61
+
The {productname} {release-version} release includes an accompanying release of the **TinyMCE AI** premium plugin.
62
+
63
+
**TinyMCE AI** includes the following fix.
64
+
65
+
==== Menus no longer close on mouse out.
66
+
// #TINY-14055
67
+
68
+
Previously, submenus in the TinyMCE AI plugin closed when the mouse pointer moved outside the menu area. This did not match the behavior of other {productname} menus, where submenus remain open until another item in the parent menu is selected or the entire menu is dismissed. The inconsistency made submenu navigation unreliable and could cause confusion during use.
69
+
70
+
In {productname} {release-version}, submenus in the TinyMCE AI plugin no longer close on mouse out. Submenus now remain open until another parent menu item is selected or the menu is dismissed, matching the behavior of all other {productname} menus.
71
+
72
+
For information on the **TinyMCE AI** plugin, see: xref:tinymceai.adoc[TinyMCE AI].
73
+
74
+
75
+
=== TinyMCE AI
76
+
77
+
The {productname} {release-version} release includes an accompanying release of the **TinyMCE AI** premium plugin.
78
+
79
+
**TinyMCE AI** includes the following fix.
80
+
81
+
==== The first loading card during a review no longer appears focused
82
+
// #TINY-14077
83
+
84
+
Previously, when running an AI review, the first skeleton card displayed in the Review sidebar while suggestions were being generated appeared with focus styles applied. Since the card content was still loading and could not be interacted with, the visible focus indicator was misleading and created a confusing user experience.
85
+
86
+
In {productname} {release-version}, focus styles are no longer applied to loading cards in the Review sidebar. Cards only receive focus styling once their content has fully loaded and they can be interacted with.
87
+
88
+
For information on the **TinyMCE AI** plugin, see: xref:tinymceai.adoc[TinyMCE AI].
89
+
90
+
91
+
=== TinyMCE AI
92
+
93
+
The {productname} {release-version} release includes an accompanying release of the **TinyMCE AI** premium plugin.
94
+
95
+
**TinyMCE AI** includes the following addition.
96
+
97
+
==== New commands for executing AI UI actions
98
+
// #TINY-14266
99
+
100
+
Previously, Quick Actions in TinyMCE AI could only be triggered through the plugin's built-in menus and toolbar buttons. Integrators who wanted to invoke these actions from custom UI elements or automation workflows had no programmatic way to do so.
101
+
102
+
In {productname} {release-version}, the TinyMCE AI plugin registers a set of editor commands that mirror each Quick Action. These include commands for built-in actions such as `TinyMCEAIQuickActionImproveWriting`, `TinyMCEAIQuickActionCheckGrammar`, and `TinyMCEAIQuickActionTranslate` (which accepts a language argument), as well as `TinyMCEAIQuickActionCustom` for running a custom prompt with a specified model. A `TinyMCEAIChatPrompt` command is also available for sending a prompt directly to the Chat sidebar. For the full list of commands, see xref:tinymceai.adoc#tinymceai-plugin-commands[TinyMCE AI plugin commands].
103
+
104
+
For information on the **TinyMCE AI** plugin, see: xref:tinymceai.adoc[TinyMCE AI].
105
+
106
+
107
+
=== TinyMCE AI
108
+
109
+
The {productname} {release-version} release includes an accompanying release of the **TinyMCE AI** premium plugin.
110
+
111
+
**TinyMCE AI** includes the following addition.
112
+
113
+
==== New optional `id` property to `tinymceai_quickactions_custom` to register the action as custom menu item
114
+
// #TINY-14229
115
+
116
+
Previously, custom quick actions defined through the xref:tinymceai.adoc#tinymceai_quickactions_custom[`+tinymceai_quickactions_custom+`] option could only appear inside a dedicated Custom submenu within the Quick Actions menu. This limited integrators who wanted custom actions to appear as top-level menu items alongside predefined actions or in other menu configurations.
117
+
118
+
In {productname} {release-version}, an optional `id` property can be included in each custom quick action object. When an `id` is set, the custom action can be listed in the xref:tinymceai.adoc#tinymceai_quickactions_menu[`+tinymceai_quickactions_menu+`] array as its own top-level menu item, or included in any menubar menu or menu button configuration that accepts control identifiers.
119
+
120
+
For information on the **TinyMCE AI** plugin, see: xref:tinymceai.adoc[TinyMCE AI].
121
+
122
+
123
+
=== TinyMCE AI
124
+
125
+
The {productname} {release-version} release includes an accompanying release of the **TinyMCE AI** premium plugin.
126
+
127
+
**TinyMCE AI** includes the following fix.
128
+
129
+
==== Loader in the chat was normal size instead of small size
130
+
// #TINY-14155
131
+
132
+
Previously, the loading spinner displayed in the AI Chat area while generating a response used the default size rather than the small size. This caused the spinner to appear visually larger than the adjacent AI response icon, creating an inconsistent appearance within the chat interface.
133
+
134
+
In {productname} {release-version}, the AI Chat loading spinner is now sized to match the AI response icon dimensions, providing a consistent and polished visual experience.
135
+
136
+
For information on the **TinyMCE AI** plugin, see: xref:tinymceai.adoc[TinyMCE AI].
137
+
138
+
139
+
=== TinyMCE AI
140
+
141
+
The {productname} {release-version} release includes an accompanying release of the **TinyMCE AI** premium plugin.
142
+
143
+
**TinyMCE AI** includes the following improvement.
144
+
145
+
==== While the plugin is generating a review or quick action, the Stop button in the loading indicator receives focus
146
+
// #TINY-14083
147
+
148
+
Previously, the TinyMCE AI plugin displayed the “Stop generating” control inconsistently across different contexts. The review loading indicator used a text-based button, while the AI Chat sidebar used an icon-based button. In addition, the control did not receive focus when it appeared, which negatively impacted keyboard accessibility.
149
+
150
+
In {productname} {release-version}, the stop button in the loading indicator now matches the icon button used in the AI Chat sidebar, providing a more consistent visual experience. The button also receives focus when displayed, improving keyboard navigation and accessibility during content generation.
151
+
152
+
For information on the **TinyMCE AI** plugin, see: xref:tinymceai.adoc[TinyMCE AI].
@@ -88,6 +198,11 @@ For information on using Enhanced Skins & Icon Packs, see: xref:enhanced-skins-a
88
198
89
199
// CCFR here.
90
200
201
+
=== Updated the Review list accordion item background color
202
+
// #TINY-14158
203
+
204
+
The background color of accordion items in the TinyMCE AI Review list has been updated from `#F7F7F7` to `#F0F0F0` to improve visual contrast and align with the current design specifications.
205
+
91
206
92
207
[[removed]]
93
208
== Removed
@@ -117,6 +232,20 @@ Previously, certain combinations of `+div+` elements inside list items could pre
117
232
118
233
In {productname} {release-version}, the list detection logic now correctly identifies when a `+div+` is inside a list and locates the parent list before treating the element as a host. Lists with nested `+div+` elements can now be toggled off as expected.
119
234
235
+
=== Script and style elements would incorrectly be removed by DOMPurify when considered valid in the schema
236
+
// #TINY-9655
237
+
238
+
Previously, `script` and `style` elements that were explicitly allowed through xref:content-filtering.adoc#valid_elements[`+valid_elements+`] or xref:content-filtering.adoc#extended_valid_elements[`+extended_valid_elements+`] were removed during the sanitization process when xref:content-filtering.adoc#xss_sanitization[`+xss_sanitization+`] was enabled. DOMPurify flagged these elements as potential mXSS vectors and removed them entirely, even when the schema configuration indicated they were valid.
239
+
240
+
In {productname} {release-version}, `script` and `style` elements that are considered valid in the schema are retained during sanitization. The sanitization process still removes unsafe attributes and content, but no longer removes the entire element when the schema explicitly allows it.
241
+
242
+
=== Iframe elements with children would incorrectly be removed by DOMPurify
243
+
// #TINY-9655
244
+
245
+
Previously, `iframe` elements that contained child nodes were removed entirely during the sanitization process. DOMPurify treated the presence of child nodes within an `iframe` as a potential mXSS risk and stripped the entire element from the content.
246
+
247
+
In {productname} {release-version}, `iframe` elements are preserved during sanitization. Any child nodes and unsafe or invalid attributes are removed, but the `iframe` element itself remains in the editor content.
**Certain elements may be removed by XSS sanitization**
44
-
By default, {productname} sanitizes HTML content to protect against XSS attacks. Elements outside the HTML5 specification, such as `<script>`, are removed. Standard `<meta>` tags are preserved, but attributes not defined in the HTML5 spec (for example, the RDFa `property` attribute) require explicit configuration to be retained.
44
+
By default, {productname} sanitizes HTML content to protect against XSS attacks. Elements outside the HTML5 specification, such as `<script>`, are removed unless explicitly allowed through xref:content-filtering.adoc#valid_elements[`+valid_elements+`] or xref:content-filtering.adoc#extended_valid_elements[`+extended_valid_elements+`]. Standard `<meta>` tags are preserved, but attributes not defined in the HTML5 spec (for example, the RDFa `property` attribute) require explicit configuration to be retained.
45
45
46
46
If integrators encounter issues with required elements being removed, the following configuration options are available. These options reduce security and should be used with caution:
0 commit comments