プロジェクト

全般

プロフィール

Vote #78681

未完了

Links to Wiki pages of unauthorized projects should be smarter

Admin Redmine さんが約2年前に追加. 約2年前に更新.

ステータス:
New
優先度:
通常
担当者:
-
カテゴリ:
Wiki_1
対象バージョン:
-
開始日:
2022/05/09
期日:
進捗率:

0%

予定工数:
category_id:
1
version_id:
0
issue_org_id:
26530
author_id:
150486
assigned_to_id:
0
comments:
6
status_id:
1
tracker_id:
2
plus1:
0
affected_version:
closed_on:
affected_version_id:
ステータス-->[New]

説明

I use to define a 'Sidebar' wiki page that contains links to wiki pages in various subprojects. This allows users to quickly jump to specific topics.

However, when migrating from Redmine 3.3.1 to 3.4.2, links to unauthorized subprojects got broken. (See here http://www.mimworld.org). Once an user has logged in and has the necessary access rights to visit the specific wiki pages, the links are displayed correctly.

Has this change been made intentional (to overcome some security problem) or is it a real bug? If this behaviour is intended, I have to rethink the entire structure of my project(s). A quick fix is much appreciated.


journals

Ouch... this issue seems to be related to r16283 and #23793 which fixes an information leak.

I wonder what this leak actually is since the user will see the link (in wiki format) anyway.

If - for whatever reason - the link is not allowed to become an HTML link then I suggest making the textual representation a bit more user-friendly. A phrase like

<pre>
[[model-repository:Latest_Model|Latest Model]]
</pre>

is something that I would not like to see in a rendered Wiki page.

--------------------------------------------------------------------------------
The attached patch results in smarter "non-links".
--------------------------------------------------------------------------------

--------------------------------------------------------------------------------
What happened to this patch?
--------------------------------------------------------------------------------
I think the patch suggested in #26530#note-2 cause an information leak. A user who is not allowed to see the wiki can probe if a given page exists.
--------------------------------------------------------------------------------
I make the plugin that disable r16283 and include wiki-links-patch.diff.
Please see https://github.com/crosspoints/redmine_legacy_link
--------------------------------------------------------------------------------

Admin Redmine さんが約2年前に更新

  • カテゴリWiki_1 にセット

他の形式にエクスポート: Atom PDF

いいね!0
いいね!0