Skip to content

Security

This page lists what DXPR Builder protects on its own, and what you decide: who may edit, whether visitor output runs through text format filters, and which files editors may upload.

Builder output and text formats

The builder saves a page as HTML in the field and shows that HTML as stored. Text format filters do not run on builder fields by default. A user who has Edit with DXPR Builder and may edit a page can therefore add any HTML to it, including scripts in an HTML element. Grant the permission to trusted roles only; Drupal marks it as restricted on the permissions page.

Apply text format filters to frontend content, under DXPR Studio > DXPR Builder > General Settings > Text Filters, runs the field's text format for users who are not editors. Editors keep seeing the raw content. A restrictive format can also strip builder markup, so test pages with it on.

AI output has its own filter. Under DXPR Studio > DXPR Builder > AI, AI Output Filtering limits generated content to the Allowed domains you list.

User permissions

DXPR Builder defines three permissions:

Permission Label Grants
edit with dxpr builder Edit with DXPR Builder Use the builder on content the user may edit; every such account uses a licence
administer dxpr builder configuration Administer DXPR Builder configuration General Settings, AI settings, User Licenses, Content items and Migrations
administer dxpr_builder_profile Administer dxpr builder profile User Profiles

The Page Templates and User Templates admin pages need the core permission Administer site configuration.

The editor also needs update access to the content itself, such as Basic page: Edit any content. Every save checks it again on the server.

AJAX routes and CSRF protection

These routes accept requests only with a CSRF token and only from an account that has Edit with DXPR Builder and is not excluded from editing:

  • /dxpr_builder/ajax (saving, templates, blocks and Views)
  • /dxpr_builder/ajax/ai/chat (AI text assistant)
  • /dxpr_builder/ajax/ai/image (AI image generation)
  • /dxpr_builder/ajax/ai/image/edit (AI image editing)
  • /dxpr_builder/ajax/file_upload (file uploads)

/dxpr_builder/user-settings and /dxpr_builder/entity-link-suggestions also require a token and the permission. The editor fetches fresh tokens from /dxpr_builder/csrf, which answers only accounts that may edit. /dxpr_builder/media-library needs View media. No manual configuration is needed.

User profiles

User profiles shape the editor for each role: which Elements, Blocks, Views, Page templates, Global user templates and Icon sets editors see, and which text editor buttons they get. A profile is not a security boundary. The save route accepts any HTML from a user with the permission, so hiding the HTML element does not stop a determined editor. More than one profile needs the DXPR Enterprise tier.

File uploads

The upload route /dxpr_builder/ajax/file_upload:

  • Accepts only GIF, JPEG, PNG, WebP, AVIF and SVG images, and WebM, Ogg, MP4 and QuickTime videos, through Drupal's file upload validation.
  • Limits the file size to PHP's upload limit.
  • Stores files in dxpr_builder_images, dxpr_builder_videos or dxpr_builder_files in the default files directory, as permanent files.

SVG files can contain scripts that run when someone opens the file directly. That is one more reason to keep the editing permission to trusted roles.

On a site whose default file system is private, files in the private dxpr_builder_images and dxpr_builder_videos folders are served to every visitor, because builder pages show them publicly. Do not upload confidential files through the builder.

What's next?

Performance tuning for faster pages to continue exploring DXPR Builder.

Something wrong or missing on this page? Report it or edit the page.