AddThisFeature

Rich Text Editor

Formatting tools that don't let pasted HTML wreck your app.

involved Forms & Input

What it adds

A WYSIWYG editor for long-form fields, with a fixed set of supported formats and server-side sanitisation of everything it produces.

What your agent is told to do

5
  1. 1

    Decide the supported format list first — headings, bold, italic, lists, links, quotes, code, images — and build the toolbar from it. An editor that accepts anything is an editor you cannot sanitise.

  2. 2

    Sanitise on the server against an allowlist of tags and attributes, both on save and on render. Client-side sanitisation is a convenience, not a defence; the endpoint accepts whatever is posted to it.

  3. 3

    Clean pasted content: strip inline styles, font tags, class names and comments from Word and Google Docs, and map what remains onto the supported formats.

  4. 4

    Keep the editable region a real focusable control with a label, and make every toolbar action reachable by keyboard with its shortcut shown.

  5. 5

    Do not store rendered HTML as the only copy if the app also needs plain text for search, previews or notifications — derive and store that too.

Edge cases it handles

6
  • Content that looks empty but is a stray break or empty paragraph must count as empty for validation.
  • Links must be checked for scheme — javascript: and data: URLs are the whole attack.
  • Pasted images arrive as base64 or as remote URLs; decide whether to upload, rewrite or reject them, and never hotlink silently.
  • Undo must survive a paste-and-clean operation as a single step, not unwind character by character.
  • Autosave and formatting must not fight: a save mid-edit should not move the caret or reset the selection.
  • Content authored before this editor existed must still open and save without being mangled.

Definition of done

8
  • Stored HTML is sanitised server-side against an explicit allowlist.
  • Pasted Word and Docs content arrives clean and mapped to supported formats.
  • Unsafe link schemes are rejected on save and on render.
  • Every toolbar action has a keyboard path and headings produce real heading elements.
  • Visually-empty content fails a required-field check.
  • Legacy content round-trips through the editor unchanged.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.