Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsFCKeditorFCKeditorBrowse Server shows links to disabled pagesBrowse Server shows links to disabled pages
Previous
 
Next
New Post
10/4/2007 5:22 PM
 

Hi,

In FCKEditor, if a user adds a hyperlink and clicks "Browse Server" for pages to link to, it seems that ALL pages are available in the dropdown box. This includes pages that are set to Disabled and pages that are not viewable by that user's role.

How can this be fixed so that

  • Disabled pages are not visible in this dropdown (should only be visible by Admin -> pages, right?)
  • Pages available in the "Select A Web Page From Your Site" selector are limited to those viewable by the user

Interestingly, when I do this in the FCKEditor I'm using on dotnetnuke.com to write this post, the list of pages available to link to is pretty short. So DNN.com might be doing something about this issue already.

Thanks in advance,
Ari

 
New Post
10/14/2007 7:43 PM
 

This is a pretty important security hole in the link selection for the FCK, IMHO. I don't think that users should be able to link to pages that they don't have permissions for. (Of course, if they don't have permissions, then at least they wont be able to actually view the pages... That's a good thing.)

Does anyone else know if this is a "known issue" or if there is a fix for this?

 
New Post
10/29/2007 7:30 PM
 

Hi Ari,

 

Good post.  I also would like to know the answer to this.  Is anyone on the FCK team listening here!?

Thanks,

 

Rod

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsFCKeditorFCKeditorBrowse Server shows links to disabled pagesBrowse Server shows links to disabled pages


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out