Custom Fields: Add warning to Finder option about information disclosure #42111
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Pull Request for Issue #42076 .
Summary of Changes
5.0 comes with the new feature that you can index the value from a custom field to a content item. Due to structural limitations, this value is indexed with the same viewing permissions as the content item it is attached to. If your custom field is more restrictive than the viewing level of the content item, this might lead to unwanted information disclosure. It is NOT possible to prevent this in code, so this PR adds a warning label to the option to make people aware of this.
Testing Instructions
Codereview?
Actual result BEFORE applying this Pull Request
No warning below the "Search Index" option in a custom field.
Expected result AFTER applying this Pull Request
Warning below the "Search Index" option.
Link to documentations
Please select:
Documentation link for docs.joomla.org:
No documentation changes for docs.joomla.org needed
Pull Request link for manual.joomla.org:
No documentation changes for manual.joomla.org needed