View Issue Details

IDProjectCategoryView StatusLast Update
0004450Composrcorepublic2020-10-24 23:49
ReporterChris GrahamAssigned ToChris Graham 
SeverityFeature-request 
Status resolvedResolutionfixed 
Product Version10.0.33 
Fixed in Version10.0.34 
Summary0004450: Improve handling around lost/missing Comcode permissions
Description1) If a user does not have privilege to bypass the HTML inclusion-list, then try and simplify down overly-complex HTML to something that matches it, with special care to images and links.
2) Add an HTML comment when something is filtered so webmasters can see a cause in the HTML source.
3) If a staff member adds a Comcode page, then subsequently is deleted or loses HTML/Comcode-dangerous privileges, it will cause an issue after the Comcode Page cache is flushed. Store a flag in the database that indicates they had those privileges at the time of them editing the page and let that flag take precedence when repopulating the cache.
TagsNo tags attached.
Time estimation (hours)
Sponsorship open

Activities

admin

2020-10-24 23:49

administrator   ~0006780

Fixed in git commit a12252d2f (https://gitlab.com/composr-foundation/composr/commit/a12252d2f - link will become active once code pushed to GitLab)

A hotfix (a TAR of files to upload) has been uploaded to this issue. These files are made to the latest intra-version state (i.e. may roll in earlier fixes too if made to the same files) - so only upload files newer than what you have already. If there are files in a hot-fix that you don't have then they probably relate to addons that you don't have installed and should be skipped. Always take backups of files you are replacing or keep a copy of the manual installer for your version, and only apply fixes you need. These hotfixes are not necessarily reliable or well supported. Not sure how to extract TAR files to your Windows computer? Try 7-zip (http://www.7-zip.org/).

admin

2020-10-24 23:49

administrator  

hotfix-4450, 2020-10-24 11pm.tar (8,859,136 bytes)

Issue History

Date Modified Username Field Change