Relax XSS Validation for Email Addresses in Text Input and Text Area
Updated
Guided Workflows use Cross-Site Scripting (XSS) validation to help prevent potentially unsafe HTML content from being submitted through screen input components. Because content enclosed in angle brackets (< >) can be interpreted as HTML, it may be blocked during validation.
In some cases, agents copy content directly from email messages into workflow fields. Email addresses in the To and CC fields are often formatted within angle brackets, such as:
<user@example.com>Previously, these email addresses could fail XSS validation even though they did not contain HTML content.
To support this scenario, Guided Workflows now provide a relaxed validation option for valid email addresses enclosed in angle brackets when entered into Text Input and Text Area components.
Example
Consider the following email content:
To: <john@example.com>
CC: <support@example.com>
Please review the issue mentioned below.
When this content is pasted into a Text Input or Text Area component, the angle brackets surrounding the email addresses can be interpreted as HTML and trigger XSS validation.
When relaxed validation is enabled, valid email addresses enclosed in angle brackets are accepted, while other HTML and potentially unsafe content continue to be validated.
Enable Relaxed Validation
Starting with release 26.10, this behaviour is controlled by the following data property:
skip_xss_validation_if_invalid_email_html
Key considerations:
- The data property is enabled by default for partners in release 26.10.
- The property may be deprecated in a future release.
- To enable relaxed validation for a component, add the following property to the component's Additional configuration:
xss_relaxed_validation
Supported Components
This enhancement applies to:
- Text Input
- Text Area
Expected Behaviour
Allowed Inputs
- Valid email addresses without angle brackets
- Valid email addresses enclosed in angle brackets when relaxed validation is enabled
- Email content copied from To or CC fields that includes email addresses such as:
<email@example.com>
Validated Inputs
The following content continues to undergo XSS validation:
- HTML tags
- Potentially unsafe HTML content
- Any non-email content enclosed in angle brackets
Important Notes
- The relaxation applies only to valid email addresses enclosed in angle brackets.
- XSS validation remains enabled for all other content.
- HTML tags and potentially unsafe content continue to be validated.
- No user interface toggle is available for this feature.
- The skip_xss_validation_if_invalid_email_html data property is enabled by default for partners, so no additional configuration is typically required.
- The xss_relaxed_validation property must be added to the Additional configuration of the relevant Text Input or Text Area component.
Configuration Example
JSON
{
"xss_relaxed_validation": true
}
Benefits
Agents can paste email content that contains addresses enclosed in angle brackets without triggering unnecessary validation failures, while existing XSS protection remains in place for other content.