When disabling external resources, local images can not be inserted into Text block

Bug #1550519 reported by Son Nguyen
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mahara
Fix Released
High
Son Nguyen
15.04
Won't Fix
High
Unassigned
15.10
Won't Fix
High
Unassigned

Bug Description

Version: master (16.04), 15.04, 15.10
Platform: any
Browser: any

Steps

1. Login as a site admin, turn ON "Disable external resources in user HTML' in Administration/Site Configurations/Security Settings
2. Login as a normal user
 - edit a page
 - insert a Text block
 - insert an local image into the text editor (you can see the image in the editor)
 - click Save

Expected result
 You should see the image inside the Text block

Actual
 No image is shown

Revision history for this message
Kristina Hoeppner (kris-hoeppner) wrote :

Disabling external resources should not affect the domain on which the Mahara site is hosted.

Changed in mahara:
milestone: none → 16.04.0
importance: Undecided → High
Son Nguyen (ngson2000)
Changed in mahara:
assignee: nobody → Son Nguyen (ngson2000)
status: Confirmed → In Progress
Revision history for this message
Mahara Bot (dev-mahara) wrote : A patch has been submitted for review

Patch for "master" branch: https://reviews.mahara.org/6114

Revision history for this message
Mahara Bot (dev-mahara) wrote :

Patch for "master" branch: https://reviews.mahara.org/6115

Revision history for this message
Kristina Hoeppner (kris-hoeppner) wrote :

While it's a big issue, it's a non-issue for most people as many will allow external resources. Therefore, fixing it only in master.

Changed in mahara:
milestone: 16.04.0 → 16.10.0
Revision history for this message
Mahara Bot (dev-mahara) wrote : A change has been merged

Reviewed: https://reviews.mahara.org/6114
Committed: https://git.mahara.org/mahara/mahara/commit/4f33131feb6d7748bb7d16e37cfcb9b08102a7eb
Submitter: Robert Lyon (<email address hidden>)
Branch: master

commit 4f33131feb6d7748bb7d16e37cfcb9b08102a7eb
Author: Son Nguyen <email address hidden>
Date: Tue Mar 8 13:19:43 2016 +1300

Bug 1550519. Add some step definitions for behat tests

- Then I should see images in the block :title
- Then I should not see images in the block :title

Fix the step "I set the field ..." to assign value with double quote

behatnotneeded - the tests are in the child patch

Change-Id: I70a8fcbf46cfbff8db6d2e257b82ef0a10bfeef4

Revision history for this message
Mahara Bot (dev-mahara) wrote :

Reviewed: https://reviews.mahara.org/6115
Committed: https://git.mahara.org/mahara/mahara/commit/af88973e801a8c051248cd8b0e85afe5af539d69
Submitter: Robert Lyon (<email address hidden>)
Branch: master

commit af88973e801a8c051248cd8b0e85afe5af539d69
Author: Son Nguyen <email address hidden>
Date: Mon Mar 7 12:00:54 2016 +1300

Bug 1550519. Fix HTMLPurifier disable external resource setting.

Add behat tests

Change-Id: I905af729d2cda76d5c6ff31b29b9d21c3dc67505

Robert Lyon (robertl-9)
Changed in mahara:
status: In Progress → Fix Committed
Robert Lyon (robertl-9)
Changed in mahara:
milestone: 16.10.0 → 16.04.0
tags: added: nominatedfeature
tags: added: usermanualupdate
removed: nominatedfeature
Changed in mahara:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.