Aktionen
GX-Bug #69557
geschlossenDownload of several content manager entries is possible but shouldn't
% erledigt:
0%
Geschätzter Aufwand:
Steps to reproduce:
Betroffene Versionen:
Unbestimmt
Release Notes Langtext:
Beim Download von deaktivierten oder nicht vorhandenen Content Manager Einträgen wird nun eine 404 Seite zurückgegeben
Beschreibung
It's possible to download several content manager entries by using the following endpoint:
<shop-url>/request_port.php?module=ShopContent&action=download&coID=<content-ID>
Expectation:
Content manager entries can be downloads as long as:
- The content with the provided ID exists.
- The "customer group check" is disabled or the customer has the needed permission.
- The status of the content is active (content is visible).
In any other case, a 404 error should be returned.
Reality:
- There is no check for existing content manager entries.
- Contents can be downloaded even if the status is not visible.
- Contents can't be downloaded even if "customer group check" is enabled and the content is available for all customer groups.
Note:
Please test this with and without the "customer group check" which can be activated on the general shop configuration page.
Furthermore, please check if any logs are created when returning the 404 page.
Aktionen