-
-
Notifications
You must be signed in to change notification settings - Fork 3.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Make sure the URL installer does not allow other schemas then http and https #32087
Conversation
Co-authored-by: Brian Teeman <brian@teeman.net>
I have tested this item ✅ successfully on eae250f This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/32087. |
I have tested this item ✅ successfully on eae250f This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/32087. |
This comment was marked as abuse.
This comment was marked as abuse.
Well its still not handled as security issue but it was reported as one. ;) Given that we had some kind of not working JS "validation" we choose to move this forward to the public tracker and get it fixed anyway. |
I have tested this item ✅ successfully on e393a65 This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/32087. |
1 similar comment
I have tested this item ✅ successfully on e393a65 This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/32087. |
RTC This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/32087. |
Thanks |
Thanks @drmenzelit |
Pull Request for an Issue raised to the JSST.
Summary of Changes
Make sure the URL installer does not allow other schemas then http and https
Testing Instructions
ftp://joomla.zip
ftp://joomla.zip
again.Actual result BEFORE applying this Pull Request
There is an message but we still try to contact the FTP server
Expected result AFTER applying this Pull Request
There is now a dedicated message and we dont try to contact an FTP server
Documentation Changes Required
none