-
-
Notifications
You must be signed in to change notification settings - Fork 213
Front end preview as non-admin bypasses protection #8149
Comments
|
Element and page protection only applies to frontend users. Thus any backend user (regardless of whether he or she is an Admin) is able to view any such elements. |
|
Having such an option wouldn't make any sense. Any backend user can see any element (given the appropriate access rights) in the backend regardless of its 'protected' state. |
|
you name it: (given the appropriate access rights) |
|
The access rights have nothing to do with the visibility in the frontend though. |
|
just an example: I have made the "show unpublished" only available for admin's in the be_switch template but as i can not imagine that my usecase is too special i think having a checkbox in the system settings would not be a big deal at all. |
Only if the backend user has the right to do so. If you disable the access to the frontend users for that backend user, he cannot view the frontend as any frontend user. Otherwise if a backend user has access to the frontend users, he can log in as any frontend user, regardless of the preview mode. |
that is right. maybe i'm going to investigate more on that tomorrow. |
|
What is the status of your investigation? |
|
I still think it's a secuity-flaw |
|
@contao/developers /cc |
|
I think the suggestion is valid, but hard to change because people are very used to it
So if you want to see certain frontend pages you need to login as that user. That's actually why there is such an option, because I usually login as a user but do not show unpublished content... |
|
Changed in contao/core-bundle@426f714. |

That might be a duplicate of #567 but as that was closed 4 years ago without solution i suggest to change at least the wording.
Not only does that selection allow to show unpublished elements but also protected elements and pages.
In my use-case that's definitely a security issue - so i am going to disable the Frontendpreview completely for non-admin BE-users.
Any Info on that for contao4 is appreciated.
The text was updated successfully, but these errors were encountered: