User tests: Successful: Unsuccessful:
Pull Request for an Issue raised to the JSST.
Make sure the URL installer does not allow other schemas then http and https
ftp://joomla.zip
ftp://joomla.zip
again.There is an message but we still try to contact the FTP server
There is now a dedicated message and we dont try to contact an FTP server
none
Status | New | ⇒ | Pending |
Category | ⇒ | Administration com_installer Language & Strings Front End Plugins |
Labels |
Added:
?
?
|
I have tested this item
Lol when I reported this years ago I was told it was a non-problem and only idiots would try to use a non http prefix ...
Lol when I reported this years ago I was told it was a non-problem and only idiots would try to use a non http prefix ...
Well its still not handled as security issue but it was reported as one. ;) Given that we had some kind of not working JS "validation" we choose to move this forward to the public tracker and get it fixed anyway.
I have tested this item
I have tested this item
Status | Pending | ⇒ | Ready to Commit |
RTC
Status | Ready to Commit | ⇒ | Fixed in Code Base |
Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2021-01-24 15:54:08 |
Closed_By | ⇒ | drmenzelit | |
Labels |
Added:
?
|
Thanks
Thanks @drmenzelit
I have tested this item✅ successfully on eae250f
Tested successfully in 3.9.25-dev of 20 January using PHP 8.0.1.
This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/32087.