[MGNLETK-108] Cross site access should not possible over default site Created: 22/Nov/13 Updated: 09/Jan/14 Resolved: 07/Jan/14 |
|
| Status: | Closed |
| Project: | Extended Templating Kit (closed) |
| Component/s: | multisite |
| Affects Version/s: | 2.0.5 |
| Fix Version/s: | 2.0.16 |
| Type: | Bug | Priority: | Critical |
| Reporter: | Frank Sommer | Assignee: | Milan Divilek |
| Resolution: | Fixed | Votes: | 0 |
| Labels: | None | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Issue Links: |
|
||||||||||||||||||||||||||||||||
| Template: |
|
||||||||||||||||||||||||||||||||
| Acceptance criteria: |
Empty
|
||||||||||||||||||||||||||||||||
| Release notes required: |
Yes
|
||||||||||||||||||||||||||||||||
| Date of First Response: | |||||||||||||||||||||||||||||||||
| Description |
|
With configured cross site filter an access across sites is not possible. But there is one exception. The access with the default site is still possible. For example: |
| Comments |
| Comment by Jan Haderka [ 04/Jan/14 ] |
|
how is this resolved when there's no commit in git and no comment explaining other possible ways of fixing the issue? |
| Comment by Mikaël Geljić [ 06/Jan/14 ] |
|
My bad, pushed branch from master instead of m-m-etk-2.0.x :/ |
| Comment by Roman Kovařík [ 07/Jan/14 ] |
|
Make skipping of check for default site configurable.
|
| Comment by Roman Kovařík [ 07/Jan/14 ] |
|
TODO : Create DOCu ticket after review. |
| Comment by Milan Divilek [ 07/Jan/14 ] |
|
Reopen: remove bypassDefaultSite property from configuration. By default "default" site is always allowed. |
| Comment by Milan Divilek [ 07/Jan/14 ] |
|
Possibility of including the default site to cross-site check is left but turned off by default to prevent possible configuration issues. |