DXPR Builder: The Best Editing (AI) Experience for Drupal
Anyone without logging in could look at the background settings of a page and find the secret digital key used for the artificial intelligence services. This would allow them to read private subscription details. They could not change any settings or content.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if it has the artificial intelligence features turned on and configured with a secret key.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate DXPR Builder: The Best Editing (AI) Experience for Drupal to 2.8.1.
For developers: what the fix changed
Wraps the inclusion of AI settings and the API key in an `if ($enable_editor)` check within `DxprBuilderFormatter.php` to prevent exposing credentials to non-editors, and adds the `user.roles:authenticated` cache context.
Also in this release Fixed image style selection logic, added file usage tracking for uploaded files, and resolved various PHPStan warnings.
dxpr_builder.info.yml+1 −1dxpr_builder.install+0 −2dxpr_builder/dxpr_frontend.min.js+0 −0js/image-select.js+6 −0js/image-utils.js+4 −4modules/dxpr_builder_block/dxpr_builder_block.info.yml+1 −1modules/dxpr_builder_page/dxpr_builder_page.info.yml+1 −1src/Controller/AjaxController.php+0 −2src/Controller/UploadFileController.php+9 −0src/Form/DxprBuilderSettingsForm.php+0 −1src/Form/DxprBuilderUserTemplateForm.php+2 −1src/Plugin/Field/FieldFormatter/DxprBuilderFormatter.php+184 −184 fix