New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[5.0] Joomla Dialog for Aricles, Categories batch and Finder Index with Statistic #40359
Conversation
That needs to be killed, it's not CSP strict and by default it's an XSS vulnerability as users could execute any arbitrary code using that event. In sort all the inline events should be considered harmful and removed ASAP... |
I am fine with removing. |
If Joomla is serious about security, those vectors should be removed. My 2c |
Conflicts: administrator/components/com_finder/src/View/Index/HtmlView.php
Conflicts: build/media_source/com_content/joomla.asset.json
|
i think the b/c plugin still has a reference to this es5? |
|
hmhm, what to reference? |
|
hmm I think I comment on the wrong PR |
|
thanks, documentation update please |
|
There it is joomla/Manual#184 |
Summary of Changes
An implementation of Joomla Dialog for for Aricles, Categories batch and Finder Index with Statistic.
Depends from #40150
It works but not fully finished.It still will be need some stilyng for batch modals and solution for 'onclose'🥔joomla-cms/administrator/components/com_finder/src/View/Index/HtmlView.php
Line 183 in 0659dc2
Testing Instructions
Apply patch then apply #40150, run
npm install.Check Article, Categories batch, and Finder Index wtih Statistic popups. Versions popup
Actual result BEFORE applying this Pull Request
Works
Expected result AFTER applying this Pull Request
Works
Link to documentations
Please select: