Hi all,
we're using the Customer Frontend for different customer services and forms via ACL.
Eg Customer A can use a form that is available via ACL that Customer B can't use.
However I noticed that in the source code of the website (HTML view), there are all forms visible no matter if hidden via ACL or not. Of course it cant be used but it is still visible.
This could be a serious security threat if there are e.g. dynamic fields with customer-internal information available in ACL forms.
Is there any way to disable this? So that the content will not be transferred to the frontend if ACL doesn't hit?
ACL transfers hidden fields to frontend
Moderator: crythias
ACL transfers hidden fields to frontend
You do not have the required permissions to view the files attached to this post.
-
- Administrator
- Posts: 4232
- Joined: 18 Dec 2007, 12:23
- Znuny Version: Znuny and Znuny LTS
- Real Name: Roy Kaldung
- Company: Znuny
- Contact:
Re: ACL transfers hidden fields to frontend
Hi,
Which add-ons do you have installed?
- Roy
Which add-ons do you have installed?
- Roy
Znuny and Znuny LTS running on CentOS / RHEL / Debian / SLES / MySQL / PostgreSQL / Oracle / OpenLDAP / Active Directory / SSO
Use a test system - always.
Do you need professional services? Check out https://www.znuny.com/
Do you want to contribute or want to know where it goes ?
Use a test system - always.
Do you need professional services? Check out https://www.znuny.com/
Do you want to contribute or want to know where it goes ?
-
- Znuny superhero
- Posts: 656
- Joined: 24 Feb 2012, 03:58
- Znuny Version: LTS and Features
- Real Name: Mo Azfar
- Location: Kuala Lumpur, MY
- Contact:
Re: ACL transfers hidden fields to frontend
This look like OTOBO instead of Znuny 

My Github
OTRS CE/LTS Discord Channel
Cant Update Package Anymore ? Check This
Professional OTRS, Znuny & OTOBO services: efflux.de/en
Free and premium add-ons: English
OTRS CE/LTS Discord Channel
Cant Update Package Anymore ? Check This
Professional OTRS, Znuny & OTOBO services: efflux.de/en
Free and premium add-ons: English
Re: ACL transfers hidden fields to frontend
Hi, yes this is OTOBO. This community is way better than otobo forum
So far everything I found here could be used in OTOBO

-
- Znuny Employee
- Posts: 147
- Joined: 13 Sep 2021, 09:38
- Znuny Version: Znuny 6.3.x
- Real Name: Shawn Beasley
- Company: Znuny
Re: ACL transfers hidden fields to frontend
Welcome! Try our Discord Server as well. https://discord.gg/zyTTeFVAHi, yes this is OTOBO. This community is way better than otobo forumSo far everything I found here could be used in OTOBO