Skip to content

Switching grid layout doesn't check for CE compatibility #52

Description

@YKWeyer

Description

It is possible to set distinct allowed/disallowed rules for columns in different backend layouts. It is also possible to reuse colPos between different layouts in order to perform some mapping when switching the layout of an existing Grid Element.

But as far as I could test, there is no check of the allowed/disallowed ContentElements in the new layout when switching, causing forbidden ContentElements being kept in columns they are not allowed in. This could be used by editors as a way to bypass defined limitations and embed ContentElements in columns they shouldn't be.

How to reproduce

(Tested with a basic ddev deployment, TYPO3 11.5.30, GridElements 11.1.0)

  1. Create two distinct CE Backend Layouts, one having fewer allowed CTypes in its columns than the other.
    For example:
    mod.web_layout.BackendLayouts {
      2columngrid {
        title = 2-Column grid
        config {
          backend_layout {
            colCount = 2
            rowCount = 1
            rows {
              1 {
                columns {
                  1 {
                    name = Left
                    colPos = 10
                    allowed {
                      CType = header,text,textpic,image,textmedia
                    }
                  }
                  2 {
                    name = Right
                    colPos = 30
                    allowed {
                      CType = header,text,textpic,image,textmedia
                    }
                  }
                }
              }
            }
          }
        }
      }
      3columngrid {
        title = 3-Column grid
        config {
          backend_layout {
            colCount = 3
            rowCount = 1
            rows {
              1 {
                columns {
                  1 {
                    name = Left
                    colPos = 10
                    allowed {
                      CType = header,text
                    }
                  }
                  2 {
                    name = Center
                    colPos = 20
                    allowed {
                      CType = header,text
                    }
                  }
                  3 {
                    name = Right
                    colPos = 30
                    allowed {
                      CType = header,text
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
    
  2. Create a new 2-Column-Grid
  3. Add a new textmedia ContentElement in one of the two columns
  4. Edit the 2-Column-Grid and turn it into a 3-Column-Grid
  5. The textmedia will remain in the same column
    • I would have expected it to land in the -2 column (for unused/disabled elements)

Possible remediation

If you think this is something worth fixing in the extension, I could extend AfterDatabaseOperations::setUnusedElements in order to perform that check, and move all disallowed ContentElements to the -2 column (with their former value saved in backupColPos).

Let me know what you think :)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions