diff --git a/core/config.class.inc.php b/core/config.class.inc.php index c988b954b..b8be9b093 100644 --- a/core/config.class.inc.php +++ b/core/config.class.inc.php @@ -1765,8 +1765,8 @@ class Config 'security.disable_joined_classes_filter' => [ 'type' => 'bool', 'description' => 'If true, scope filters aren\'t applied to joined classes or union classes not directly listed in the SELECT clause.', - 'default' => true, - 'value' => true, + 'default' => false, + 'value' => false, 'source_of_value' => '', 'show_in_conf_sample' => false, ], @@ -1781,8 +1781,8 @@ class Config 'security.disable_exec_forced_login_for_all_enpoints' => [ 'type' => 'bool', 'description' => 'If true, when no delegated authentication module is defined, no login will be forced on modules exec endpoints', - 'default' => true, - 'value' => true, + 'default' => false, + 'value' => false, 'source_of_value' => '', 'show_in_conf_sample' => false, ], diff --git a/core/dbobjectsearch.class.php b/core/dbobjectsearch.class.php index 08164adff..c62892016 100644 --- a/core/dbobjectsearch.class.php +++ b/core/dbobjectsearch.class.php @@ -1945,7 +1945,7 @@ class DBObjectSearch extends DBSearch $oSearch = $this; $aClassesToFilter = $this->GetSelectedClasses(); - // Opt-in for joined classes filtering, otherwise only filter the selected class(es) + // Joined classes filtering can be disabled through the configuration. if (MetaModel::GetConfig()->Get('security.disable_joined_classes_filter') === false) { $aClassesToFilter = $this->GetJoinedClasses(); } diff --git a/core/dbunionsearch.class.php b/core/dbunionsearch.class.php index 9e808183a..4ec5d6dff 100644 --- a/core/dbunionsearch.class.php +++ b/core/dbunionsearch.class.php @@ -683,7 +683,7 @@ class DBUnionSearch extends DBSearch return $this; } - // Opt-in for joined classes filtering, otherwise fallback on DBSearch filtering + // Joined classes filtering can be disabled through the configuration. if (MetaModel::GetConfig()->Get('security.disable_joined_classes_filter') === true) { return parent::ApplyDataFilters(); } diff --git a/tests/php-unit-tests/integration-tests/login-tests/LoginWebPageTest.php b/tests/php-unit-tests/integration-tests/login-tests/LoginWebPageTest.php index 45ad48d6b..397aead2f 100644 --- a/tests/php-unit-tests/integration-tests/login-tests/LoginWebPageTest.php +++ b/tests/php-unit-tests/integration-tests/login-tests/LoginWebPageTest.php @@ -111,7 +111,7 @@ class LoginWebPageTest extends ItopDataTestCase $this->assertStringContainsString('iTop login', $sPageContent, 'if itop is configured to force login when no there is no delegated authentication endpoints list, then login should be required.'); } - public function testWithoutDelegatedAuthenticationEndpointsListWithDefaultConfiguration() + public function testWithoutDelegatedAuthenticationEndpointsListRequiresLoginByDefault() { $sPageContent = $this->CallItopUri( "pages/exec.php?exec_module=extension-without-delegated-authentication-endpoints-list&exec_page=src/Controller/File.php", @@ -120,7 +120,24 @@ class LoginWebPageTest extends ItopDataTestCase true ); - $this->assertStringContainsString('Yo', $sPageContent, 'by default (until N°9343) if no delegated authentication endpoints list is defined, not logged in persons should access pages'); + $this->assertStringContainsString('iTop login', $sPageContent, 'by default, login should be required when no delegated authentication endpoints list is defined'); + } + + public function testWithoutDelegatedAuthenticationEndpointsListWithCompatibilityOptOut() + { + @chmod($this->oConfig->GetLoadedFile(), 0770); + $this->oConfig->Set('security.disable_exec_forced_login_for_all_enpoints', true, 'AnythingButEmptyOrUnknownValue'); + $this->oConfig->WriteToFile(); + @chmod($this->oConfig->GetLoadedFile(), 0444); + + $sPageContent = $this->CallItopUri( + "pages/exec.php?exec_module=extension-without-delegated-authentication-endpoints-list&exec_page=src/Controller/File.php", + [], + [], + true + ); + + $this->assertStringContainsString('Yo !', $sPageContent, 'the compatibility opt-out should allow anonymous access when no delegated authentication endpoints list is defined'); } public function testNotInDelegatedAuthenticationEndpointsList()