[MGNLSTK-800] ClassCastException in STK Demo Project when retrieving paragraph through URL Created: 29/Sep/11  Updated: 04/Nov/15  Resolved: 04/Nov/15

Status: Closed
Project: Magnolia Standard Templating Kit (closed)
Component/s: None
Affects Version/s: 1.4.5
Fix Version/s: None

Type: Bug Priority: Neutral
Reporter: Edgar Vonk Assignee: Philipp Bärfuss
Resolution: Won't Do Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified
Environment:

Mac OS Lion, Magnolia Community 4.4.5, Tomcat Bundle


Attachments: File catalina.out    
Template:
Acceptance criteria:
Empty
Date of First Response:

 Description   

On the default Magnolia Community 4.4.5 with the STK JARs installed when I retrieve this paragraph using the URL:
http://localhost:8080/magnoliaPublic/demo-project/news-and-events/main/0

I see in the logs:
java.lang.ClassCastException: info.magnolia.module.templatingkit.paragraphs.EventsListModel cannot be cast to info.magnolia.module.templatingkit.templates.STKTemplateModel

I am not sure if this is a bug in the STK but it seems so?

If so, this can be quite harmfull for existing Magnolia (STK) sites I think. It should be fairly easy to think of a DoD attack using such paragraph URLs. The log file will flood in no time I think.

On a side note: I wonder if it is a good idea to 'enable' these paragraph URLs by default? It is not wise to disable this feature by default and let people explicitly enable it? Because this bug shows it can be quite risky?

I have attached the log file.



 Comments   
Comment by Michael Mühlebach [ 04/Nov/15 ]

Given the thousands of other issues we have open that are more highly requested, we won't be able to address this issue in the foreseeable future. Instead we will focus on issues with a higher impact, and more votes.
Thanks for taking the time to raise this issue. As you are no doubt aware this issue has been on our backlog for some time now with very little movement.
I'm going to close this to set expectations so the issue doesn't stay open for years with few updates. If the issue is still relevant please feel free to reopen it or create a new issue.

Generated at Mon Feb 12 07:30:32 CET 2024 using Jira 9.4.2#940002-sha1:46d1a51de284217efdcb32434eab47a99af2938b.