Helix Ultimate 2.2.9 - Custom Code field converts script tags to s-cript on save - Forum | JoomShaper
Solved Helix Framework

Helix Ultimate 2.2.9 - Custom Code field converts script tags to s-cript on save

Asked by Selwynn 2 months ago Last activity 2 months ago

Hi JoomShaper Team,After updating Helix Ultimate to version 2.2.9 on Joomla 5, entering custom JavaScript inside Template Options $\rightarrow$ Custom Code (Before </head> or Before </body>) automatically inserts a hyphen into the JavaScript opening tag upon saving (converting s c r i p t to s - c r i p t).

This prevents the JavaScript from executing on the front end and renders raw text output on the page. Please advise if a hotfix will be issued for the framework sanitizer.Thanks!

Accepted answer

Marked as the solution
Paul Frankowski Senior Staff
2 months ago · edited

@Selwynn @Justion In 99% cases it's caused by default RSFirewall settings. We even have info inside our documenation, as well as RSJoomla.

RSFirewall changes two popular tags to <i-frame> and <s-cript> to block code injections. To stop this, add your IP to the safelist in settings, create an exception for the specific component, or adjust the active scanner settings. That's all.

4 more replies

Toufiq Senior Staff

Hi there,

Thank you for reaching out, and I apologize for any inconvenience caused by this oversight. I have checked it my local environment and it works fine.

https://prnt.sc/iRdffiKb__h1

Best regards,

Toufiqur Rahman (Team Lead, Support)

Selwynn Asked this

Hi Toufiq,

Thank you for testing this so quickly! The issue seems to occur specifically on live server environments where active security filters like the one am currently using, RSFirewall inspect POST requests. When saving through Template Options -> Custom Code, those security layers intercept the raw script tags and sanitize them to s-cript before saving to the database.

I am using Stratos templete, if this helps.

Toufiq Senior Staff

In this case you need to contact your RSFirewall support. Ask them how to bypass it. Thanks

Justin

@Selwynn, did you sort this out? I'm running into the same issue ... even after uninstalling RSFirewall I'm still running into a glitch where template settings are lost, including custom code.

Justin

Thanks Paul,

I believe disabling 'Enable Active Scanner in the /administrator section' in the Active Scanner tab of the Firewall Configuration does indeed solve the issue.

Paul Frankowski Senior Staff

Mark topic as solved. You're welcome.

Log in to reply.