Unanticipated User Role setting causes error
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 3/5
- Geschätzter Aufwand
- 1-2 Tage
- Anfängerfreundlichkeit
- 38/100
- Issue-Typ
- Bug
- Klarheit
- Klar beschrieben
- Aktivitätsstatus
- Veraltet
- Tech-Stack
- php
- Bereich
- authorization, backend
Rechercherichtung
Beginne in CommentingPlugin::showComments und vergleiche views/public/comments.php mit der vorgeschlagenen views/public/commentingHeader.php. Verfolge die Rollenprüfungen für das Anzeigen und Hinzufügen von Kommentaren und überprüfe anschließend, dass eine Rolle, die kommentieren darf, aber Kommentare nicht anzeigen darf, weiterhin das Label, die Flash-Nachricht und das Kommentarformular ohne Fehler erhält.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
I came across an issue which gets triggered by the scenario that a certain User Role is able to make a comment, but not allowed to view them. In this case the $view variable along with $view->addHelperPath is not set since this is currently dependent on the ability to view comments. Also in this scenario the Label as well as the flash message does not get output, since they currently reside in views/public/comments.php, which gets bypassed.
To fix the issue, I updated the showComments function in CommentingPlugin to the following:
public static function showComments($args = array())
{
echo "<div id='comments-container'>";
// presume we will need the view in any case
if(isset($args['view'])) {
$view = $args['view'];
} else {
$view = get_view();
}
$view->addHelperPath(COMMENTING_PLUGIN_DIR . '/helpers', 'Commenting_View_Helper_');
// output the header
echo $view->partial('commentingHeader.php');
if( (get_option('commenting_allow_public') == 1)
|| (get_option('commenting_allow_public_view') == 1)
|| is_allowed('Commenting_Comment', 'show') ) {
$options = array('threaded'=> get_option('commenting_threaded'), 'approved'=>true);
$comments = isset($args['comments']) ? $args['comments'] : $view->getComments($options);
echo $view->partial('comments.php', array('comments'=>$comments, 'threaded'=>$options['threaded']));
}
if( (get_option('commenting_allow_public') == 1)
|| is_allowed('Commenting_Comment', 'add') ) {
echo "<div id='comment-main-container'>";
echo $view->getCommentForm();
echo "</div>";
}
echo "</div>";
}
This presumes that we need the $views set in any case.
I also created a new file views/public/commentingHeader.php which contains:
<?php $label = get_option('commenting_comments_label'); ?>
<?php if ($label == ''):?>
<h2><?php echo __('Comments'); ?></h2>
<?php else: ?>
<h2><?php echo $label; ?></h2>
<?php endif; ?>
<div id='comments-flash'><?php echo flash(true); ?></div>
This code has been removed from views/public/comments.php.
- Vorherrschende Sprache
- PHP
- Sterne
- 4
- Forks
- 5
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Entwicklungsumgebung
Dieses Projekt bietet weder Dev-Container noch Dockerfile noch Beitragsleitfaden – die Einrichtung liegt bei Ihnen. Beginnen Sie mit der README; die allgemeinen Schritte stehen in unserem Leitfaden für den ersten Beitrag.
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus omeka/plugin-Commenting
-
Rearrange configOffen
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 42/100
omeka/plugin-Commenting#59 ·
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 45/100
omeka/plugin-Commenting#58 ·
-
User role issuesOffen
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 35/100
omeka/plugin-Commenting#57 ·
-
Comment div bumps prev/next nav inappropriatelyEvtl. wieder frei @patrickmj hat das vor 3168 Tagen übernommen, und es ist kein Pull Request offen. Offen
omeka/plugin-Commenting#41 · 1 zugewiesene Person ·
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 20/100
omeka/plugin-Commenting#26 · 3 Kommentare ·
Alle Issues in omeka/plugin-Commenting
Ähnliche Issues
-
sync-en
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
Maintainer antworten meist innerhalb von 1 Tag
-
bug Feature: Kiosk
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
Maintainer antworten meist innerhalb von 1 Tag
-
Infrastructure: actions Module: zmscitizenapi Module: zmsentities php Type: Bug unit tests
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
it-at-m/eappointment#3480 ·
Maintainer antworten meist innerhalb von 1 Tag
-
HttpClient
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
Maintainer antworten meist innerhalb von 1 Tag
-
CI: composer install fails — league/flysystem 1.x blocked by security advisory GHSA-cxf4-7mrp-vvprOffendevops type: bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
Maintainer antworten meist innerhalb von 1 Tag