Copied to clipboard

Flag this post as spam?

This post will be reported to the moderators as potential spam to be looked at


  • Sjors Pals 617 posts 270 karma points
    Sep 09, 2009 @ 14:31
    Sjors Pals
    4

    Alttemplate problem (possible security flaw?)

    Today i noticed that when using alt template the allowed templates (for that documenttype) is bypassed, this means that any template can be used on any item.

    In 99% of the cases this is no problem, but in some cases it can be, IE when you make a viewreport template, which displays sensitive data, and you use that template on a secured node, the template can still be used on a an other page, so keep this in mind, when you are developing templates!

  • Douglas Robar 3570 posts 4711 karma points MVP ∞ admin c-trib
    Sep 09, 2009 @ 15:05
    Douglas Robar
    0

    I agree, alternate templates should honor the list of specifically allowed templates for a docType. Can you add this to Codeplex as a bug report?

    cheers,
    doug.

  • Sjors Pals 617 posts 270 karma points
    Sep 09, 2009 @ 15:24
    Sjors Pals
    0

    Ok Douglas, will submit this.

  • Sjors Pals 617 posts 270 karma points
    Sep 09, 2009 @ 15:31
  • Stephan Lonntorp 195 posts 212 karma points
    Oct 03, 2009 @ 09:27
    Stephan Lonntorp
    0

    When I did the Level 2 course, Niels commented on this as being by design, and leaving it up to the developer to make sure that security scenarios like thses doesn't happen.

Please Sign in or register to post replies

Write your reply to:

Draft