ACL transfers hidden fields to frontend

Moderator: crythias

Post Reply
dscfrnt
Znuny newbie
Posts: 7
Joined: 14 Nov 2024, 20:53
Znuny Version: LTS 6.5.11
Real Name: David

ACL transfers hidden fields to frontend

Post by dscfrnt »

Hi all,

we're using the Customer Frontend for different customer services and forms via ACL.
Eg Customer A can use a form that is available via ACL that Customer B can't use.

However I noticed that in the source code of the website (HTML view), there are all forms visible no matter if hidden via ACL or not. Of course it cant be used but it is still visible.

This could be a serious security threat if there are e.g. dynamic fields with customer-internal information available in ACL forms.

Is there any way to disable this? So that the content will not be transferred to the frontend if ACL doesn't hit?
You do not have the required permissions to view the files attached to this post.
root
Administrator
Posts: 4232
Joined: 18 Dec 2007, 12:23
Znuny Version: Znuny and Znuny LTS
Real Name: Roy Kaldung
Company: Znuny
Contact:

Re: ACL transfers hidden fields to frontend

Post by root »

Hi,

Which add-ons do you have installed?

- Roy
Znuny and Znuny LTS running on CentOS / RHEL / Debian / SLES / MySQL / PostgreSQL / Oracle / OpenLDAP / Active Directory / SSO

Use a test system - always.

Do you need professional services? Check out https://www.znuny.com/

Do you want to contribute or want to know where it goes ?
skullz
Znuny superhero
Posts: 656
Joined: 24 Feb 2012, 03:58
Znuny Version: LTS and Features
Real Name: Mo Azfar
Location: Kuala Lumpur, MY
Contact:

Re: ACL transfers hidden fields to frontend

Post by skullz »

This look like OTOBO instead of Znuny :o
My Github
OTRS CE/LTS Discord Channel
Cant Update Package Anymore ? Check This

Professional OTRS, Znuny & OTOBO services: efflux.de/en
Free and premium add-ons: English
dscfrnt
Znuny newbie
Posts: 7
Joined: 14 Nov 2024, 20:53
Znuny Version: LTS 6.5.11
Real Name: David

Re: ACL transfers hidden fields to frontend

Post by dscfrnt »

Hi, yes this is OTOBO. This community is way better than otobo forum ;) So far everything I found here could be used in OTOBO
shawnbeasley
Znuny Employee
Posts: 147
Joined: 13 Sep 2021, 09:38
Znuny Version: Znuny 6.3.x
Real Name: Shawn Beasley
Company: Znuny

Re: ACL transfers hidden fields to frontend

Post by shawnbeasley »

Hi, yes this is OTOBO. This community is way better than otobo forum ;) So far everything I found here could be used in OTOBO
Welcome! Try our Discord Server as well. https://discord.gg/zyTTeFVA
Post Reply