User tests: Successful: Unsuccessful:
Pull Request for an Issue raised to the JSST.
Make sure the URL installer does not allow other schemas then http and https
ftp://joomla.zipftp://joomla.zip again.There is an message but we still try to contact the FTP server
There is now a dedicated message and we dont try to contact an FTP server
none
| Status | New | ⇒ | Pending | 
| Category | ⇒ | Administration com_installer Language & Strings Front End Plugins | 
| Labels | Added: 
?
? | ||
 
                 
                I have tested this item 
 
                Lol when I reported this years ago I was told it was a non-problem and only idiots would try to use a non http prefix ...
 
                Lol when I reported this years ago I was told it was a non-problem and only idiots would try to use a non http prefix ...
Well its still not handled as security issue but it was reported as one. ;) Given that we had some kind of not working JS "validation" we choose to move this forward to the public tracker and get it fixed anyway.
 
                I have tested this item 
 
                I have tested this item 
| Status | Pending | ⇒ | Ready to Commit | 
 
                RTC
| Status | Ready to Commit | ⇒ | Fixed in Code Base | 
| Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2021-01-24 15:54:08 | 
| Closed_By | ⇒ | drmenzelit | |
| Labels | Added: 
? | ||
 
                Thanks
 
                Thanks @drmenzelit
I have tested this item✅  successfully on eae250f
Tested successfully in 3.9.25-dev of 20 January using PHP 8.0.1.
This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/32087.