Skip to content

Fixed: The dialogs of the online editor open for whoever may edit the version being edited, and a pasted style without a colon gives no warning - #138

Closed
fwoldt wants to merge 2 commits into
se7enxweb:mainfrom
fwoldt:fix/ezoe-dialogs-and-pasted-styles
Closed

fwoldt wants to merge 2 commits into
se7enxweb:mainfrom
fwoldt:fix/ezoe-dialogs-and-pasted-styles

Conversation

@fwoldt

@fwoldt fwoldt commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

What changed

Dialogs of the online editor. ezoe/dialog and ezoe/relations opened only for whoever may read the object.
Someone who edits a draft of an object that was never published can not read the object yet (it has no location).
So the dialogs to insert a link, an image or an embedded object refused two groups of editors:

  • the editors of such a draft;
  • the editors an extension lets in through the filter content/edit/access.

Uploads (ezoe/upload) and custom tags (ezoe/tags) already let both groups in through
eZContentObject::editAccess(). The new Exponential\View\Extension\Ezoe\Ezoe\Dialog::mayOpen() allows reading the
object or editing the version being edited, and both views use it.

Pasted styles. eZOEInputParser::elementStylesToAttribute() split each style declaration at every colon:

  • A declaration without one (style="color; text-align: right", common in content pasted from a word processor)
    raised "Undefined array key 1" and a trim() deprecation.
  • A value lost everything after its first colon.

It splits at the first colon now and leaves out a declaration without one. Two related cases are already handled
and stay as they are:

  • characters XML does not allow are removed from the whole input (eZXMLInputParser);
  • a style name that can not be an attribute is left out without making the input invalid.

How it was tested

  • expOEDialogAccessTest (new, live, with users of its own that are removed again):
    • the dialogs open for whoever may read the object;
    • they open for whoever may edit the version but not read the object, which the old check refused;
    • they open for neither a user without read and edit access, nor a version that does not exist, nor a missing
      object.
  • expOEPastedStylesTest (new): a declaration without a colon, a value with colons, names that can not be
    attributes, and control characters. Each case is checked for no PHP warning, valid input, and stored XML that loads
    again. It fails without the change.
  • ezoe suite: the same results as on main, apart from the 8 new tests.
  • phpcs: no new violations.

felix added 2 commits October 7, 2026 11:45
… version being edited, and a pasted style without a colon gives no warning

ezoe/dialog and ezoe/relations opened only for whoever may read the object. Someone who edits a draft of an object
that was never published can not read it yet (it has no location), so the dialogs to insert a link, an image or an
embedded object refused the editors of such a draft, and the editors an extension lets in through the filter
content/edit/access, while uploads and custom tags already let them in. Dialog::mayOpen() allows reading the object
or editing the version being edited, and both views use it.

eZOEInputParser::elementStylesToAttribute() split each pasted style declaration at every colon: a declaration
without one raised "Undefined array key 1" and a trim() deprecation, and a value lost everything after its first
colon. It splits at the first colon now and leaves out a declaration without one. Characters XML does not allow are
already removed from the whole input, and a name that can not be an attribute is already left out.
… access, the pasted style fix, their tests and changelog
se7enxweb added a commit that referenced this pull request Oct 7, 2026
…yles

The dialogs of the online editor open for whoever may read the object, and
otherwise only on the user's own draft of it, decided as content/edit
decides it, including language limitations. A pasted style becomes an
attribute only with a plain property name, an alignment only with a
keyword, and the dialog name in the address must be a plain template name.
Reviewed in three rounds, with tests that run without a database and the
live tests run against an installation.
@se7enxweb

Copy link
Copy Markdown
Owner

Merged into main as a3f4fb5 (rebased onto main after #136, so GitHub does not detect the merge itself). Both commits are kept with their author; on top of them, three review rounds: the dialogs now open for who may not read the object only on their own draft, decided as content/edit decides it (version, status, creator, trash, language limitations); a pasted style becomes an attribute only with a plain property name and an alignment only with a keyword (browser prefixes removed); the dialog name in the address must be a plain template name. Tests that run without a database were added, and the live ezoe tests were run against an installation. Follow-ups outside this PR (upload/tags dialogs per version, attribute escaping in the editor markup) are tracked separately.

@se7enxweb se7enxweb closed this Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants