Repository navigation
Fixed: The dialogs of the online editor open for whoever may edit the version being edited, and a pasted style without a colon gives no warning - #138
Conversation
… version being edited, and a pasted style without a colon gives no warning ezoe/dialog and ezoe/relations opened only for whoever may read the object. Someone who edits a draft of an object that was never published can not read it yet (it has no location), so the dialogs to insert a link, an image or an embedded object refused the editors of such a draft, and the editors an extension lets in through the filter content/edit/access, while uploads and custom tags already let them in. Dialog::mayOpen() allows reading the object or editing the version being edited, and both views use it. eZOEInputParser::elementStylesToAttribute() split each pasted style declaration at every colon: a declaration without one raised "Undefined array key 1" and a trim() deprecation, and a value lost everything after its first colon. It splits at the first colon now and leaves out a declaration without one. Characters XML does not allow are already removed from the whole input, and a name that can not be an attribute is already left out.
… access, the pasted style fix, their tests and changelog
…yles The dialogs of the online editor open for whoever may read the object, and otherwise only on the user's own draft of it, decided as content/edit decides it, including language limitations. A pasted style becomes an attribute only with a plain property name, an alignment only with a keyword, and the dialog name in the address must be a plain template name. Reviewed in three rounds, with tests that run without a database and the live tests run against an installation.
|
Merged into main as a3f4fb5 (rebased onto main after #136, so GitHub does not detect the merge itself). Both commits are kept with their author; on top of them, three review rounds: the dialogs now open for who may not read the object only on their own draft, decided as content/edit decides it (version, status, creator, trash, language limitations); a pasted style becomes an attribute only with a plain property name and an alignment only with a keyword (browser prefixes removed); the dialog name in the address must be a plain template name. Tests that run without a database were added, and the live ezoe tests were run against an installation. Follow-ups outside this PR (upload/tags dialogs per version, attribute escaping in the editor markup) are tracked separately. |
What changed
Dialogs of the online editor.
ezoe/dialogandezoe/relationsopened only for whoever may read the object.Someone who edits a draft of an object that was never published can not read the object yet (it has no location).
So the dialogs to insert a link, an image or an embedded object refused two groups of editors:
content/edit/access.Uploads (
ezoe/upload) and custom tags (ezoe/tags) already let both groups in througheZContentObject::editAccess(). The newExponential\View\Extension\Ezoe\Ezoe\Dialog::mayOpen()allows reading theobject or editing the version being edited, and both views use it.
Pasted styles.
eZOEInputParser::elementStylesToAttribute()split each style declaration at every colon:style="color; text-align: right", common in content pasted from a word processor)raised "Undefined array key 1" and a
trim()deprecation.It splits at the first colon now and leaves out a declaration without one. Two related cases are already handled
and stay as they are:
eZXMLInputParser);How it was tested
expOEDialogAccessTest(new, live, with users of its own that are removed again):object.
expOEPastedStylesTest(new): a declaration without a colon, a value with colons, names that can not beattributes, and control characters. Each case is checked for no PHP warning, valid input, and stored XML that loads
again. It fails without the change.