Microsoft Lists Formatting: Update to filepreview elmType in custom formatters

  • Home |
  • Microsoft Lists Formatting: Update to filepreview elmType in custom formatters
SharePoint Curtain Reveal Tech Bulletin Header

SharePoint Online, SharePoint Development Services

From Microsoft Corporation
Technical Bulletin MC397486 · Published Jul 5, 2022

Message Summary

Custom Formatters allow users to write declarative JSON to emit HTML. The “filepreview” elmType was introduced to show thumbnails in SharePoint document libraries with a fallback “fileType icon” for the cases when thumbnails aren’t available.

We came across a usage of this feature that allowed embedding external URLs on a SharePoint list. While we understand the powerful scenarios this could open up, we would want to make sure we permit it post due diligence and after addressing any security concerns.

As an immediate step, we are restricting the feature to what it was initially intended to achieve, i.e., to show file thumbnails/previews.

When this will happen:

This change has been rolled out and we apologize for not providing notice prior.

How this will affect your organization:

All URLs other than those which match the ones for thumbnails will be blocked. Users will not be able to embed external resources like SharePoint pages, lists, WXP files, Stream videos and YouTube videos on a SharePoint list.

At a late time, we will allow-list the URLs in a phased manner after ensuring the feature does not expose any security loopholes or lead to performance degradation. A separate communication will follow for the same. 

What you need to do to prepare:

No action is required. You may consider notifying users about this change and update your training and documentation as appropriate.

More information:

y

Recent Comments

No comments to show.

Recent Posts

Microsoft 365 Curtain Reveal Tech Bulletin Header
New Outlook for Windows: Auto-reading emails with Microsoft Windows Narrator
October 14, 2024
Microsoft 365 Curtain Reveal Tech Bulletin Header
(Updated) Microsoft Purview: Minor encrypted message portal design updates, URL to remain the same
October 14, 2024
Microsoft Exchange Curtain Reveal Tech Bulletin Header
(Updated) Microsoft Defender for Office 365: Tenant Allow/Block List will support IPv6 allow and block entries
October 14, 2024