Configuration file

Contents

Configure Content Studio by adding properties to its configuration file. Each setting below describes the behavior it controls.

Add config properties to this file:
$XP_HOME/config/com.enonic.app.contentstudio.cfg

Max file upload size

uploadMaxFileSize = 100mb

Sets the maximum size of an individual uploaded file. The limit applies to attachments, media content, and project and content thumbnails. The default is 100mb.

Disable path name transliteration

contentWizard.allowPathTransliteration=false

By default, Content Studio transliterates characters when generating an item’s path name from its display name. Set contentWizard.allowPathTransliteration to false to disable this conversion. The display name itself is unaffected.

Publishing Wizard

These settings control readiness actions, scheduling, and the initial dependency selection in the Publishing wizard.

Disable "Mark as Ready" action

publishingWizard.allowContentUpdate = false

By default, the Publishing wizard offers a bulk Mark as ready action when the batch contains In progress items. Set publishingWizard.allowContentUpdate to false to disable this bulk action. Users must then open and mark each item ready individually before publishing it.

This setting does not change the readiness or validation requirements for publishing. See Mark as ready for the available actions.

Default "Online from" time

publishingWizard.defaultPublishFromTime = 12:00

Sets the default time offered when choosing an Online from date for scheduled publishing. Use the 24-hour format HH:mm; the default is 12:00. Users can change the time before confirming the schedule.

This setting does not automatically schedule content for that time. Without an explicit start date and time, Online from uses Now unless the field is configured as required below.

Required "Online from"

publishingWizard.requiredPublishFrom = true

By default, publishingWizard.requiredPublishFrom is false: users can leave Online from unset when scheduling, which means Now. Set it to true to require an explicit start date and time before a schedule can be confirmed.

This requirement applies when scheduling; it does not disable the Publish now action.

Exclude optional dependencies

publishingWizard.excludeDependencies = false

Controls whether optional dependencies are initially selected for publishing. The default is true: optional dependencies, such as referenced content, appear in the wizard but are left unchecked. Users choose which ones to include.

Set publishingWizard.excludeDependencies to false to preselect optional dependencies as well. Users can still exclude optional items before publishing. Required dependencies, such as ancestors needed to preserve the content tree, remain included regardless of this setting.

See Publishing dependencies for reviewing and changing the batch.

Content Security Policy

Content Security Policy (CSP) controls which scripts, styles, images, frames, and network connections a page may use. Content Studio applies a policy to its interface, while content rendered through the XP Site service preview has a separate policy.

Both policies can be customized in com.enonic.app.contentstudio.cfg.

Extensions

Applications contribute extensions to Content Studio, such as Context panels. Extensions rendered inside the Content Studio interface must comply with its CSP. Loading scripts, calling APIs, or embedding frames from external domains may require additional allowed sources.

Customize the policy

Set contentSecurityPolicy.header to allow the resources your extensions need while keeping CSP enabled. For example, this policy allows connections to https://api.example.com alongside the sources used by Content Studio:

contentSecurityPolicy.header = default-src 'self'; connect-src 'self' ws: wss: https://market.enonic.com https://api.example.com; script-src 'self' 'unsafe-inline'; object-src 'none'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:

Replace the example API origin with the required origin. Keep the configured Market API origin if your installation uses a different one. Use script-src for scripts, connect-src for API connections, and frame-src for embedded frames.

In Content Studio 6.0, contentSecurityPolicy.header replaces the complete default policy. Include all directives and sources needed by Content Studio as well as the extension; a single extra directive is not appended to the default.

The Google Analytics app is an example of an extension that loads external resources. See its CSP configuration example for the sources it requires.

Disable the policy

To disable Content Studio’s own CSP, set:

contentSecurityPolicy.enabled = false

Customizing the allowed sources keeps the rest of the policy in effect. Disabling this policy does not disable the separate XP Site service preview policy.

XP Site service preview

The XP Site service preview mode renders content using XP’s Site service. The Preview panel displays it in an iframe, while the Preview action opens it in a separate tab. These previews run under the admin origin, so their resource requirements may differ from those of the public site.

Use site.preview.contentSecurityPolicy to customize the fallback policy for this content. In Content Studio 6.0, it applies in preview and inline modes when the rendered response does not already provide a Content-Security-Policy header. If the application supplies its own header, its developers must update that policy instead.

For example, this preview policy allows scripts from https://cdn.example.com:

site.preview.contentSecurityPolicy = default-src 'self'; base-uri 'self'; form-action 'self'; script-src 'self' https://cdn.example.com; object-src 'none'; img-src * data:; style-src * 'unsafe-inline'; font-src * data:

This setting supplies a complete fallback policy. Adjust the required resource directives and keep the remaining restrictions appropriate for the site.

Visual editing in the Page Editor uses its own CSP. Neither contentSecurityPolicy.header nor site.preview.contentSecurityPolicy customizes that editing policy.

Legacy and deprecated features

Enable Rich Text component

settings.enableTextComponent=true

The Rich Text component was deprecated in Content Studio 6.0. The setting above re-enables insertion of this component. See Text component for its behavior.


Contents

Contents