Bug #18797

"New page" wizard might disclose existence of pages outside DB mount

Added by Christian Lerrahn about 14 years ago. Updated almost 4 years ago.

Status:
Closed
Priority:
Should have
Assignee:
Category:
Backend User Interface
Target version:
-
Start date:
2008-05-15
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
6.2
PHP Version:
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

When creating a new page inside the top level of a DB mount which is only a sub tree, the pages up and down from the DB mount root will be displayed in the position selector if the logged in user has read permissions for these pages. This is unwanted information disclosure as the permissions should not matter for pages which are outside the DB mount.

Example:
Tree looks like
x -
- a
- b
- d
- e
- f
- c

User A has b as his DB mount but reading permissions on all pages in the tree. He now create a new page inside b. The position selector should only show him b and its subpages. Instead he will be shown a and c, too.
(issue imported from #M8428)


Files

Cattura.PNG (5.15 KB) Cattura.PNG Riccardo De Contardi, 2013-05-15 17:10
Cattura2.PNG (11.8 KB) Cattura2.PNG Riccardo De Contardi, 2013-05-15 17:10
Cattura3.PNG (9.87 KB) Cattura3.PNG Riccardo De Contardi, 2013-05-15 17:10

Related issues

Related to TYPO3 Core - Bug #59427: Hook in calcPerms was not called anymoreRejectedStefan Froemken2014-06-10

Actions
Blocks TYPO3 Core - Bug #63047: TreeView with non pages isInWebMount wrong parameter because of Bugfix #18797Closed2014-11-18

Actions
#1

Updated by Sebastian Virus almost 12 years ago

Still exists in Typo3 4.3.5

#2

Updated by Alexander Opitz about 9 years ago

  • Status changed from New to Needs Feedback
  • Target version deleted (0)

The issue is very old, does this issue exists in newer versions of TYPO3 CMS (4.5 or 6.1)?

#3

Updated by Riccardo De Contardi about 9 years ago

See attached files to see what happens in TYPO3 6.1.0:

1. Cattura.PNG
is a branch of my pagetree; the editor's usergroup has B1 as DB mount.

2. Cattura2.PNG
if I click > page actions > new --> the wizard shown is what the user sees.
If I click on the arrow that allows me to add a page as sibling of B1 (see red circle on attached file) then there is an error:

3. Cattura3.PNG
The error reports the name of the parent of B1.

#4

Updated by Alexander Opitz about 9 years ago

  • Status changed from Needs Feedback to New
#5

Updated by Nicole Cordes about 9 years ago

  • Category set to Backend User Interface
  • Status changed from New to Accepted
  • Assignee set to Nicole Cordes
  • Target version set to 6.2.0
  • TYPO3 Version changed from 4.1 to 6.2
  • PHP Version deleted (5.2)
#6

Updated by Gerrit Code Review almost 9 years ago

  • Status changed from Accepted to Under Review

Patch set 1 for branch master has been pushed to the review server.
It is available at https://review.typo3.org/22632

#7

Updated by Ernesto Baschny almost 9 years ago

  • Target version deleted (6.2.0)

Good catch, but I would only backport until 6.0. Let's focus on more important tasks than backporting to 4.x from now on.

#8

Updated by Gerrit Code Review over 8 years ago

Patch set 2 for branch master has been pushed to the review server.
It is available at https://review.typo3.org/22632

#9

Updated by Gerrit Code Review over 8 years ago

Patch set 3 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/22632

#10

Updated by Gerrit Code Review over 8 years ago

Patch set 4 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/22632

#11

Updated by Gerrit Code Review over 8 years ago

Patch set 1 for branch TYPO3_6-1 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/27429

#12

Updated by Gerrit Code Review over 8 years ago

Patch set 1 for branch TYPO3_6-0 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/27430

#13

Updated by Nicole Cordes over 8 years ago

  • Status changed from Under Review to Resolved
  • % Done changed from 0 to 100
#14

Updated by Benni Mack almost 4 years ago

  • Status changed from Resolved to Closed

Also available in: Atom PDF