Skip to main content

Display view files with extra param

More
3 hours 16 minutes ago #100000044 by oxido
-- HikaShop version -- : 6.6.0
-- Joomla version -- : 5.4.8
-- PHP version -- : 8.3.33
-- Browser(s) name and version -- : Chrome 154.0

Hi there,
Regarding that HikaShop setting that allows you to see view blocks on the front-end: even though the setting can be disabled, I believe that front-end view editing should only be possible if you are logged in as an Administrator.
As it stands, if the option is enabled, anyone with access to the site who adds the relevant parameter to the URL can access and modify the code.
I know the setting isn't meant to stay on all the time, but things happen, and it is possible to accidentally leave that option enabled.

It's just my concern. B)

Please Log in or Create an account to join the conversation.

More
51 minutes ago #100000046 by nicolas
Hi,

The setting only prints, on the page, the name of the template file used for each block, together with a small edit icon; it does not make editing possible from the front-end. That icon points to a backend (administrator) URL, and opening the Joomla backend always requires being logged in there, independently of this HikaShop setting. Without a valid backend login, clicking the icon only opens the Joomla administrator login screen, never the file's content, so a visitor who is not logged into the backend cannot read or change the code through it, even with the option left enabled and the extra URL parameter added. It is still good practice to turn the option off once you are done debugging, and the 'with extra parameter in the URL' mode you are likely thinking of is already the least exposed of the available choices, since it only shows this information when that specific parameter is added to the URL.
The following user(s) said Thank You: oxido

Please Log in or Create an account to join the conversation.

Time to create page: 0.169 seconds
Powered by Kunena Forum