[MAGNOLIA-3753] Restriction of paragraphs per template can be bypassed by changing the template, using a restricted paragraph and changing back Created: 04/Jul/11  Updated: 04/Nov/15  Resolved: 04/Nov/15

Status: Closed
Project: Magnolia
Component/s: admininterface, rendering
Affects Version/s: 4.4.4
Fix Version/s: None

Type: Improvement Priority: Neutral
Reporter: Maximilian St√∂rzer Assignee: Philipp Bärfuss
Resolution: Won't Do Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Template:
Acceptance criteria:
Empty
Task DoD:
[ ]* Doc/release notes changes? Comment present?
[ ]* Downstream builds green?
[ ]* Solution information and context easily available?
[ ]* Tests
[ ]* FixVersion filled and not yet released
[ ]  Architecture Decision Record (ADR)
Date of First Response:

 Description   

Hi Magnolia team,

our authors are very "creative" in abusing the system. Currently we face the following problem: A certain paragraph (FckEditor as is) may only be used in content temapltes. However we have a structurally very similar page für navigation contents, where this paragraph must not be used.

To bypass the paragraph restriction, our authors do the following:

  • Set the page template to "Content Page"
  • Add the restricted paragraph
  • Change the template back to "Navigation Page"
    The restricted paragrah reders perfectly fine.

Now this is of course not the intention of this restriction. Is there a way to enforce paragraph template restrictions such that the descibed bypass is no longer possible?

Thanks & best regards
Max Störzer



 Comments   
Comment by Jan Haderka [ 04/Jul/11 ]

Hi Maximilian,

thanks for reporting the problem.
Unfortunately, there is currently no easy way to fix this issue apart from checking for the type of the parent page in the paragraph itself and refusing to render it in case parent page is not of the expected type.

HTH,
Jan

Comment by Michael Mühlebach [ 04/Nov/15 ]

Given the thousands of other issues we have open that are more highly requested, we won't be able to address this issue in the foreseeable future. Instead we will focus on issues with a higher impact, and more votes.
Thanks for taking the time to raise this issue. As you are no doubt aware this issue has been on our backlog for some time now with very little movement.
I'm going to close this to set expectations so the issue doesn't stay open for years with few updates. If the issue is still relevant please feel free to reopen it or create a new issue.

Generated at Mon Feb 12 03:49:21 CET 2024 using Jira 9.4.2#940002-sha1:46d1a51de284217efdcb32434eab47a99af2938b.