Configuration file
Contents
Configure Content Studio by adding properties to its configuration file. Each setting below describes the behavior it controls.
$XP_HOME/config/com.enonic.app.contentstudio.cfg
Max file upload size
uploadMaxFileSize = 100mb
Sets the maximum size of an individual uploaded file. The limit applies to attachments, media content, and project and content thumbnails. The default is 100mb.
Disable path name transliteration
contentWizard.allowPathTransliteration=false
By default, Content Studio transliterates characters when generating an item’s path name from its display name. Set contentWizard.allowPathTransliteration to false to disable this conversion. The display name itself is unaffected.
Publishing Wizard
These settings control readiness actions, scheduling, and the initial dependency selection in the Publishing wizard.
Disable "Mark as Ready" action
publishingWizard.allowContentUpdate = false
By default, the Publishing wizard offers a bulk Mark as ready action when the batch contains In progress items. Set publishingWizard.allowContentUpdate to false to disable this bulk action. Users must then open and mark each item ready individually before publishing it.
This setting does not change the readiness or validation requirements for publishing. See Mark as ready for the available actions.
Default "Online from" time
publishingWizard.defaultPublishFromTime = 12:00
Sets the default time offered when choosing an Online from date for scheduled publishing. Use the 24-hour format HH:mm; the default is 12:00. Users can change the time before confirming the schedule.
This setting does not automatically schedule content for that time. Without an explicit start date and time, Online from uses Now unless the field is configured as required below.
Required "Online from"
publishingWizard.requiredPublishFrom = true
By default, publishingWizard.requiredPublishFrom is false: users can leave Online from unset when scheduling, which means Now. Set it to true to require an explicit start date and time before a schedule can be confirmed.
This requirement applies when scheduling; it does not disable the Publish now action.
Exclude optional dependencies
publishingWizard.excludeDependencies = false
Controls whether optional dependencies are initially selected for publishing. The default is true: optional dependencies, such as referenced content, appear in the wizard but are left unchecked. Users choose which ones to include.
Set publishingWizard.excludeDependencies to false to preselect optional dependencies as well. Users can still exclude optional items before publishing. Required dependencies, such as ancestors needed to preserve the content tree, remain included regardless of this setting.
See Publishing dependencies for reviewing and changing the batch.
Content Security Policy
Content Security Policy (CSP) controls which scripts, styles, images, frames, and network connections a page may use. Content Studio applies a policy to its interface, while content rendered through the XP Site service preview has a separate policy.
Both policies can be customized in com.enonic.app.contentstudio.cfg.
Extensions
Applications contribute extensions to Content Studio, such as Context panels. Extensions rendered inside the Content Studio interface must comply with its CSP. Loading scripts, calling APIs, or embedding frames from external domains may require additional allowed sources.
Customize the policy
Set contentSecurityPolicy.header to allow the resources your extensions need while keeping CSP enabled. For example, this policy allows connections to https://api.example.com alongside the sources used by Content Studio:
contentSecurityPolicy.header = default-src 'self'; connect-src 'self' ws: wss: https://market.enonic.com https://api.example.com; script-src 'self' 'unsafe-inline'; object-src 'none'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:
Replace the example API origin with the required origin. Keep the configured Market API origin if your installation uses a different one. Use script-src for scripts, connect-src for API connections, and frame-src for embedded frames.
In Content Studio 6.0, contentSecurityPolicy.header replaces the complete default policy. Include all directives and sources needed by Content Studio as well as the extension; a single extra directive is not appended to the default. |
The Google Analytics app is an example of an extension that loads external resources. See its CSP configuration example for the sources it requires.
Disable the policy
To disable Content Studio’s own CSP, set:
contentSecurityPolicy.enabled = false
Customizing the allowed sources keeps the rest of the policy in effect. Disabling this policy does not disable the separate XP Site service preview policy.
XP Site service preview
The XP Site service preview mode renders content using XP’s Site service. The Preview panel displays it in an iframe, while the Preview action opens it in a separate tab. These previews run under the admin origin, so their resource requirements may differ from those of the public site.
Use site.preview.contentSecurityPolicy to customize the fallback policy for this content. In Content Studio 6.0, it applies in preview and inline modes when the rendered response does not already provide a Content-Security-Policy header. If the application supplies its own header, its developers must update that policy instead.
For example, this preview policy allows scripts from https://cdn.example.com:
site.preview.contentSecurityPolicy = default-src 'self'; base-uri 'self'; form-action 'self'; script-src 'self' https://cdn.example.com; object-src 'none'; img-src * data:; style-src * 'unsafe-inline'; font-src * data:
This setting supplies a complete fallback policy. Adjust the required resource directives and keep the remaining restrictions appropriate for the site.
Visual editing in the Page Editor uses its own CSP. Neither contentSecurityPolicy.header nor site.preview.contentSecurityPolicy customizes that editing policy. |
Legacy and deprecated features
Enable Rich Text component
settings.enableTextComponent=true
The Rich Text component was deprecated in Content Studio 6.0. The setting above re-enables insertion of this component. See Text component for its behavior.