Download the PHP package carlos-andres/nova-html-field without Composer
On this page you can find all versions of the php package carlos-andres/nova-html-field. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download carlos-andres/nova-html-field
More information about carlos-andres/nova-html-field
Files in carlos-andres/nova-html-field
Package nova-html-field
Short Description A Laravel Nova field for rendering HTML content with XSS protection
License MIT
Informations about the package nova-html-field
Nova HTML Field
A Laravel Nova 4/5 field for rendering HTML content with built-in XSS protection via HTMLPurifier.
Features
- XSS Protection - HTMLPurifier sanitization enabled by default
- Dynamic Content - Resolve HTML from model attributes or closures
- Inline Styles - Full support for inline CSS styling
- View Control - Standard Nova visibility methods
- Conditional Display - Show/hide based on request conditions
Requirements
- PHP 8.1+
- Laravel 10+
- Nova 4+ or Nova 5+
Installation
No build step required - works out of the box.
Quick Start
Usage
Static HTML with content()
Dynamic Content with html()
From Model Attribute
View Visibility
Conditional Rendering
Styling Guide
Use Inline Styles (Recommended)
Inline styles are the most reliable way to style HtmlField content:
Tailwind CSS Limitations
Tailwind utility classes (e.g., bg-blue-500, p-4, rounded-lg) will not render unless they are already included in Nova's compiled CSS bundle. Nova only includes the Tailwind classes it uses internally.
Icons and Emojis
HTMLPurifier strips SVG elements by default. Use emoji or Unicode symbols instead:
Security
Default Protection
All HTML is sanitized using HTMLPurifier:
| Threat | Protection |
|---|---|
<script> tags |
Removed |
Event handlers (onclick, onerror) |
Removed |
javascript: URLs |
Blocked |
<style>, <object>, <embed> |
Removed |
data: URLs in images |
Blocked |
| Safe HTML elements | Preserved |
| Inline styles | Preserved |
Best Practices
Always escape dynamic content:
Disable Sanitization (Trusted Content Only)
Custom Purifier Configuration
See HTMLPurifier docs for all options.
API Reference
| Method | Description |
|---|---|
content(string $html) |
Set static HTML content |
html(Closure $callback) |
Set HTML via closure (receives model) |
withoutSanitization() |
Disable HTMLPurifier (use with caution) |
purifierConfig(array $config) |
Custom HTMLPurifier settings |
when(Closure $callback) |
Show when condition is true |
unless(Closure $callback) |
Show unless condition is true |
Inherited Nova Methods
onlyOnIndex(),onlyOnDetail(),onlyOnForms()showOnIndex(),showOnDetail(),showOnCreating(),showOnUpdating()hideFromIndex(),hideFromDetail(),hideWhenCreating(),hideWhenUpdating()exceptOnForms()canSee(Closure $callback)fullWidth()help(string $text)
Testing
Note: Tests require Nova classes. Run from within a Laravel project that has Nova installed, or the tests will fail with "Class not found" errors.
Changelog
future implementation.
License
MIT License. See LICENSE for details.