Skip to content

Fix inline text editor: Google font loading - #643

Merged
uldisrudzitis merged 1 commit into
masterfrom
fix-inline-edit-font-family
Sep 30, 2026
Merged

uldisrudzitis merged 1 commit into
masterfrom
fix-inline-edit-font-family

Conversation

@uldisrudzitis

@uldisrudzitis uldisrudzitis commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary by CodeRabbit

  • Bug Fixes
    • Inline editing now uses the Google Fonts stylesheets from the preview, helping text retain its intended appearance in both plain-text and rich-text overlays.
    • Stylesheets are loaded only once, avoiding duplicate entries.

@uldisrudzitis uldisrudzitis self-assigned this Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: c05542a4-bfff-46eb-ac93-d07fce79cd13

📥 Commits

Reviewing files that changed from the base of the PR and between fad1377 and 9963f57.

📒 Files selected for processing (3)
  • editor/src/app/preview/inline-edit/inline-edit-rich-text-overlay.component.ts
  • editor/src/app/preview/inline-edit/inline-edit.service.spec.ts
  • editor/src/app/preview/inline-edit/inline-edit.service.ts

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

Inline edits now reuse Google Fonts stylesheet URLs from the preview document. Plain-text overlays load missing links into the parent document. Rich-text overlays pass stylesheet URLs to TinyMCE through content_css. The service deduplicates URLs and avoids loading links already marked in the parent document.

Changes

Inline edit font stylesheets

Layer / File(s) Summary
Font stylesheet discovery and plain-text loading
editor/src/app/preview/inline-edit/inline-edit.service.ts, editor/src/app/preview/inline-edit/inline-edit.service.spec.ts
The service extracts unique Google Fonts stylesheet URLs and adds links not already marked as loaded to the parent document. Plain-text overlay setup invokes this loading. Tests cover URL filtering, deduplication, and repeated loads.
Rich-text TinyMCE stylesheet wiring
editor/src/app/preview/inline-edit/inline-edit.service.ts, editor/src/app/preview/inline-edit/inline-edit-rich-text-overlay.component.ts
The service passes preview stylesheet URLs to the rich-text overlay. The overlay adds them to TinyMCE’s content_css alongside the default skin.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant PreviewDocument
  participant InlineEditService
  participant ParentDocument
  participant RichTextOverlay
  participant TinyMCE
  PreviewDocument->>InlineEditService: Provide Google Fonts stylesheet links
  InlineEditService->>InlineEditService: Extract unique absolute URLs
  alt Plain-text overlay
    InlineEditService->>ParentDocument: Add URLs not already marked as loaded
  else Rich-text overlay
    InlineEditService->>RichTextOverlay: Pass URLs as fontStylesheets
    RichTextOverlay->>TinyMCE: Set content_css to default skin and supplied URLs
  end
Loading

Merge Risk: ⚪ Minimal · up to 9963f

The change propagates preview Google Fonts to both inline editors. No actionable merge-blocking issue is established; merge after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 9963f

Preview font stylesheets now affect the main editor and remain loaded across plain-text edits. The inspected producers generate Google Fonts URLs, and no exploitable new attack path was established. However, accepted URL origins and stylesheet ownership depend on trust assumptions that remain incompletely verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The direct new exposure is stylesheet influence over the browser editor document and TinyMCE content. Plain-text imports have document-wide, cross-edit lifetime rather than preview-local lifetime. Broader tenant, server, or credential impact has not been established.

Trust Boundaries and Controls

  • observed — The preview already allows scripts and same-origin access, and the parent already reads and modifies its document. This PR extends that integration with stylesheet forwarding; it does not introduce the existing script or DOM authority.

Hardening Proposals

  • proposed — Make the intended provider boundary explicit by validating parsed stylesheet URLs against the expected Google Fonts origin and permitted scheme before forwarding them to either rendering context.
  • proposed — Define ownership and invalidation for the shared parent-document font cache, particularly when the active preview or site changes, so retained stylesheet authority is deliberate and bounded.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: loading Google Fonts for the inline text editor.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 3…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@uldisrudzitis
uldisrudzitis merged commit cec846b into master Sep 30, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant