[trunk] Website Builder - Sitemap - showing all links even hidden pages

Bug #1284104 reported by LisAndi - Andi Becker - http://lisandi.com
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Odoo Web (MOVED TO GITHUB)
Confirmed
Undecided
Unassigned

Bug Description

1)2)3)

If you enter yourdomain.tld/sitemap

you will get all links of pages even they are hidden and do not belong to the website builder. This can be quite dangerous as information might get exporsed which should not get exposed this way.

i.e. check out all those eMail Designer links!

 /shop/payment/validate/
/page/website.aboutus
/shop/confirm_order/
/shop/pricelist
/shop/checkout/
/shop/filters/
/shop/payment/
/shop/mycart/
/crm/contactus
/sitemap.xml
/robots.txt
/customers/
/partners/
/sitemap
/members/
/event/
/blog
/jobs
/shop/
/
/website_mail/email_designer/Application-approved-11/
/website_mail/email_designer/Application-refused-10/
/website_mail/email_designer/Confirmation-of-the-Event-13/
/website_mail/email_designer/Confirmation-of-the-Registration-14/
/website_mail/email_designer/Invoice---Send-by-Email-7/
/website_mail/email_designer/Invoice---Send-by-Email-Portal-17/
/website_mail/email_designer/Lead-Mass-Mail-12/
/website_mail/email_designer/LeadOpportunity-Mass-Mail-8/
/website_mail/email_designer/Meeting-Invitation-4/
/website_mail/email_designer/Meeting-Invitation-6/
/website_mail/email_designer/Meeting-Invitation-5/
/website_mail/email_designer/OpenERP-Enterprise-Connection-3/
/website_mail/email_designer/Partner-Mass-Mail-1/
/website_mail/email_designer/Reminder-to-User-9/
/website_mail/email_designer/Reset-Password-2/
/website_mail/email_designer/Sales-Order---Send-by-Email-15/
/website_mail/email_designer/Sales-Order---Send-by-Email-Portal-16/
/shop/category/Others-1/
/blog/News-1/
/page/website.aboutus
/page/website.contactus
/page/website.homepage
/page/website_payment.cc_form
/page/website.imprint

Changed in openerp-web:
status: New → Confirmed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.