- Posts: 280
- Thank you received: 42
Display view files with extra param
3 hours 16 minutes ago #100000044
by oxido
Display view files with extra param was created by oxido
-- HikaShop version -- : 6.6.0
-- Joomla version -- : 5.4.8
-- PHP version -- : 8.3.33
-- Browser(s) name and version -- : Chrome 154.0
Hi there,
Regarding that HikaShop setting that allows you to see view blocks on the front-end: even though the setting can be disabled, I believe that front-end view editing should only be possible if you are logged in as an Administrator.
As it stands, if the option is enabled, anyone with access to the site who adds the relevant parameter to the URL can access and modify the code.
I know the setting isn't meant to stay on all the time, but things happen, and it is possible to accidentally leave that option enabled.
It's just my concern.
-- Joomla version -- : 5.4.8
-- PHP version -- : 8.3.33
-- Browser(s) name and version -- : Chrome 154.0
Hi there,
Regarding that HikaShop setting that allows you to see view blocks on the front-end: even though the setting can be disabled, I believe that front-end view editing should only be possible if you are logged in as an Administrator.
As it stands, if the option is enabled, anyone with access to the site who adds the relevant parameter to the URL can access and modify the code.
I know the setting isn't meant to stay on all the time, but things happen, and it is possible to accidentally leave that option enabled.
It's just my concern.
Please Log in or Create an account to join the conversation.
51 minutes ago #100000046
by nicolas
Replied by nicolas on topic Display view files with extra param
Hi,
The setting only prints, on the page, the name of the template file used for each block, together with a small edit icon; it does not make editing possible from the front-end. That icon points to a backend (administrator) URL, and opening the Joomla backend always requires being logged in there, independently of this HikaShop setting. Without a valid backend login, clicking the icon only opens the Joomla administrator login screen, never the file's content, so a visitor who is not logged into the backend cannot read or change the code through it, even with the option left enabled and the extra URL parameter added. It is still good practice to turn the option off once you are done debugging, and the 'with extra parameter in the URL' mode you are likely thinking of is already the least exposed of the available choices, since it only shows this information when that specific parameter is added to the URL.
The setting only prints, on the page, the name of the template file used for each block, together with a small edit icon; it does not make editing possible from the front-end. That icon points to a backend (administrator) URL, and opening the Joomla backend always requires being logged in there, independently of this HikaShop setting. Without a valid backend login, clicking the icon only opens the Joomla administrator login screen, never the file's content, so a visitor who is not logged into the backend cannot read or change the code through it, even with the option left enabled and the extra URL parameter added. It is still good practice to turn the option off once you are done debugging, and the 'with extra parameter in the URL' mode you are likely thinking of is already the least exposed of the available choices, since it only shows this information when that specific parameter is added to the URL.
The following user(s) said Thank You: oxido
Please Log in or Create an account to join the conversation.
Time to create page: 0.169 seconds