Security
This page lists what DXPR Builder protects on its own, and what you decide: who may edit, whether visitor output runs through text format filters, and which files editors may upload.
Builder output and text formats
The builder saves a page as HTML in the field and shows that HTML as stored. Text format filters do not run on builder fields by default. A user who has Edit with DXPR Builder and may edit a page can therefore add any HTML to it, including scripts in an HTML element. Grant the permission to trusted roles only; Drupal marks it as restricted on the permissions page.
Apply text format filters to frontend content, under DXPR Studio > DXPR Builder > General Settings > Text Filters, runs the field's text format for users who are not editors. Editors keep seeing the raw content. A restrictive format can also strip builder markup, so test pages with it on.
AI output has its own filter. Under DXPR Studio > DXPR Builder > AI, AI Output Filtering limits generated content to the Allowed domains you list.
User permissions
DXPR Builder defines three permissions:
| Permission | Label | Grants |
|---|---|---|
edit with dxpr builder |
Edit with DXPR Builder | Use the builder on content the user may edit; every such account uses a licence |
administer dxpr builder configuration |
Administer DXPR Builder configuration | General Settings, AI settings, User Licenses, Content items and Migrations |
administer dxpr_builder_profile |
Administer dxpr builder profile | User Profiles |
The Page Templates and User Templates admin pages need the core permission Administer site configuration.
The editor also needs update access to the content itself, such as Basic page: Edit any content. Every save checks it again on the server.
AJAX routes and CSRF protection
These routes accept requests only with a CSRF token and only from an account that has Edit with DXPR Builder and is not excluded from editing:
/dxpr_builder/ajax(saving, templates, blocks and Views)/dxpr_builder/ajax/ai/chat(AI text assistant)/dxpr_builder/ajax/ai/image(AI image generation)/dxpr_builder/ajax/ai/image/edit(AI image editing)/dxpr_builder/ajax/file_upload(file uploads)
/dxpr_builder/user-settings and
/dxpr_builder/entity-link-suggestions also require a token and
the permission. The editor fetches fresh tokens from
/dxpr_builder/csrf, which answers only accounts that may edit.
/dxpr_builder/media-library needs View media. No manual
configuration is needed.
User profiles
User profiles shape the editor for each role: which Elements, Blocks, Views, Page templates, Global user templates and Icon sets editors see, and which text editor buttons they get. A profile is not a security boundary. The save route accepts any HTML from a user with the permission, so hiding the HTML element does not stop a determined editor. More than one profile needs the DXPR Enterprise tier.
File uploads
The upload route /dxpr_builder/ajax/file_upload:
- Accepts only GIF, JPEG, PNG, WebP, AVIF and SVG images, and WebM, Ogg, MP4 and QuickTime videos, through Drupal's file upload validation.
- Limits the file size to PHP's upload limit.
- Stores files in
dxpr_builder_images,dxpr_builder_videosordxpr_builder_filesin the default files directory, as permanent files.
SVG files can contain scripts that run when someone opens the file directly. That is one more reason to keep the editing permission to trusted roles.
On a site whose default file system is private, files in the
private dxpr_builder_images and dxpr_builder_videos folders are
served to every visitor, because builder pages show them publicly.
Do not upload confidential files through the builder.
What's next?
Performance tuning for faster pages to continue exploring DXPR Builder.