My Oracle Support Banner

CKEditor Prefixing data-cke-pa to onClick Code in HTML Tags (Doc ID 1983531.1)

Last updated on JUNE 09, 2016

Applies to:

Oracle WebCenter Sites - Version 11.1.1.8.0 and later
Information in this document applies to any platform.

Symptoms

"on*" HTML code, such as <a onClick="doSomething()">, within CKEditor is being updated to "data-cke-pa-on*" in the rendered page.

Additionally due to this bug, javascript is being commented out and encoded in a similar way.

Example:

<button data-cke-pa-onclick="myFunction()">Try it</button><div><br/></div><!--{cke_protected}%3Cscript%3E%0Afunction%20myFunction()%20%7B%0Aalert(%22I%20am%20an%20alert%20box!%22)%3B%0A%7D%0A%3C%2Fscript%3E-->

 

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Symptoms
Cause
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.