Inline media in content
Drop [media:UUID] or [media:UUID|variant] tokens into the post body, attach those files to the post’s content bucket, then render:
$image = $post->addMedia($request->file('diagram'))->toMediaBucket($post->contentBucket());
$post->setTranslation('content', 'en', "Intro [media:{$image->uuid}] outro")->save();
// With an explicit variant:
// "[media:{$image->uuid}|responsive-320]"{!! $post->renderContent() !!} {{-- current locale --}}
{!! $post->renderContent('sk') !!} {{-- a specific locale --}}- Images become responsive <img> tags with a srcset. With a variant — in the token or via posts.media.inline.default_variant — they become a plain <img> of that variant. Name one media-library generates for the content bucket (e.g. responsive-640); until it exists, or for an unknown name such as an author’s typo, the image renders from its original instead of failing the page.
- Any other file becomes a link: <a href="…">name</a>. URLs and names are escaped.
- Tokens resolve in one batched query against the post’s own content bucket — never an arbitrary global UUID.
- A token the post does not own is stripped, or kept verbatim with posts.media.inline.on_missing set to keep. Malformed tokens are left untouched.
- With posts.media.inline.enabled set to false, the content is returned as stored.
Security
renderContent() returns raw, unescaped HTML: the stored body comes back verbatim as an HtmlString that Blade does not escape — only the tokens are replaced, with escaped values. Echo it with {!! !!} only when the body is trusted (written by trusted editors) or was sanitised when it was saved. If you accept rich text from untrusted users, sanitise it at write time with an allow-list HTML sanitiser of your choice — the package never sanitises, on save or on render.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.