Description
It is possible to set distinct allowed/disallowed rules for columns in different backend layouts. It is also possible to reuse colPos between different layouts in order to perform some mapping when switching the layout of an existing Grid Element.
But as far as I could test, there is no check of the allowed/disallowed ContentElements in the new layout when switching, causing forbidden ContentElements being kept in columns they are not allowed in. This could be used by editors as a way to bypass defined limitations and embed ContentElements in columns they shouldn't be.
How to reproduce
(Tested with a basic ddev deployment, TYPO3 11.5.30, GridElements 11.1.0)
- Create two distinct CE Backend Layouts, one having fewer allowed CTypes in its columns than the other.
For example:
mod.web_layout.BackendLayouts {
2columngrid {
title = 2-Column grid
config {
backend_layout {
colCount = 2
rowCount = 1
rows {
1 {
columns {
1 {
name = Left
colPos = 10
allowed {
CType = header,text,textpic,image,textmedia
}
}
2 {
name = Right
colPos = 30
allowed {
CType = header,text,textpic,image,textmedia
}
}
}
}
}
}
}
}
3columngrid {
title = 3-Column grid
config {
backend_layout {
colCount = 3
rowCount = 1
rows {
1 {
columns {
1 {
name = Left
colPos = 10
allowed {
CType = header,text
}
}
2 {
name = Center
colPos = 20
allowed {
CType = header,text
}
}
3 {
name = Right
colPos = 30
allowed {
CType = header,text
}
}
}
}
}
}
}
}
}
- Create a new 2-Column-Grid
- Add a new
textmedia ContentElement in one of the two columns
- Edit the 2-Column-Grid and turn it into a 3-Column-Grid
- The
textmedia will remain in the same column
- I would have expected it to land in the
-2 column (for unused/disabled elements)
Possible remediation
If you think this is something worth fixing in the extension, I could extend AfterDatabaseOperations::setUnusedElements in order to perform that check, and move all disallowed ContentElements to the -2 column (with their former value saved in backupColPos).
Let me know what you think :)
Description
It is possible to set distinct allowed/disallowed rules for columns in different backend layouts. It is also possible to reuse
colPosbetween different layouts in order to perform some mapping when switching the layout of an existing Grid Element.But as far as I could test, there is no check of the
allowed/disallowedContentElements in the new layout when switching, causing forbidden ContentElements being kept in columns they are not allowed in. This could be used by editors as a way to bypass defined limitations and embed ContentElements in columns they shouldn't be.How to reproduce
(Tested with a basic ddev deployment, TYPO3
11.5.30, GridElements11.1.0)For example:
mod.web_layout.BackendLayouts { 2columngrid { title = 2-Column grid config { backend_layout { colCount = 2 rowCount = 1 rows { 1 { columns { 1 { name = Left colPos = 10 allowed { CType = header,text,textpic,image,textmedia } } 2 { name = Right colPos = 30 allowed { CType = header,text,textpic,image,textmedia } } } } } } } } 3columngrid { title = 3-Column grid config { backend_layout { colCount = 3 rowCount = 1 rows { 1 { columns { 1 { name = Left colPos = 10 allowed { CType = header,text } } 2 { name = Center colPos = 20 allowed { CType = header,text } } 3 { name = Right colPos = 30 allowed { CType = header,text } } } } } } } } }textmediaContentElement in one of the two columnstextmediawill remain in the same column-2column (for unused/disabled elements)Possible remediation
If you think this is something worth fixing in the extension, I could extend
AfterDatabaseOperations::setUnusedElementsin order to perform that check, and move all disallowed ContentElements to the-2column (with their former value saved inbackupColPos).Let me know what you think :)