From a2a00cb5826838c9100c1686ae84d6501c708d32 Mon Sep 17 00:00:00 2001 From: Stephen Abello Date: Tue, 29 Sep 2026 10:02:57 +0200 Subject: [PATCH] =?UTF-8?q?N=C2=B010075=20-=20Update=20configuration=20par?= =?UTF-8?q?ameters=20default=20value=20(#1055)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- core/config.class.inc.php | 8 +++---- core/dbobjectsearch.class.php | 2 +- core/dbunionsearch.class.php | 2 +- .../login-tests/LoginWebPageTest.php | 21 +++++++++++++++++-- 4 files changed, 25 insertions(+), 8 deletions(-) diff --git a/core/config.class.inc.php b/core/config.class.inc.php index 3c86ebdf40..c9ae978fbf 100644 --- a/core/config.class.inc.php +++ b/core/config.class.inc.php @@ -1750,8 +1750,8 @@ class Config 'security.disable_joined_classes_filter' => [ 'type' => 'bool', 'description' => 'If true, scope filters aren\'t applied to joined classes or union classes not directly listed in the SELECT clause.', - 'default' => true, - 'value' => true, + 'default' => false, + 'value' => false, 'source_of_value' => '', 'show_in_conf_sample' => false, ], @@ -1766,8 +1766,8 @@ class Config 'security.disable_exec_forced_login_for_all_enpoints' => [ 'type' => 'bool', 'description' => 'If true, when no delegated authentication module is defined, no login will be forced on modules exec endpoints', - 'default' => true, - 'value' => true, + 'default' => false, + 'value' => false, 'source_of_value' => '', 'show_in_conf_sample' => false, ], diff --git a/core/dbobjectsearch.class.php b/core/dbobjectsearch.class.php index d702c1d0bf..f79dec488e 100644 --- a/core/dbobjectsearch.class.php +++ b/core/dbobjectsearch.class.php @@ -1938,7 +1938,7 @@ class DBObjectSearch extends DBSearch $oSearch = $this; $aClassesToFilter = $this->GetSelectedClasses(); - // Opt-in for joined classes filtering, otherwise only filter the selected class(es) + // Joined classes filtering can be disabled through the configuration. if (MetaModel::GetConfig()->Get('security.disable_joined_classes_filter') === false) { $aClassesToFilter = $this->GetJoinedClasses(); } diff --git a/core/dbunionsearch.class.php b/core/dbunionsearch.class.php index 8566655aba..100fb20a0e 100644 --- a/core/dbunionsearch.class.php +++ b/core/dbunionsearch.class.php @@ -683,7 +683,7 @@ class DBUnionSearch extends DBSearch return $this; } - // Opt-in for joined classes filtering, otherwise fallback on DBSearch filtering + // Joined classes filtering can be disabled through the configuration. if (MetaModel::GetConfig()->Get('security.disable_joined_classes_filter') === true) { return parent::ApplyDataFilters(); } diff --git a/tests/php-unit-tests/integration-tests/login-tests/LoginWebPageTest.php b/tests/php-unit-tests/integration-tests/login-tests/LoginWebPageTest.php index 45ad48d6b2..397aead2fd 100644 --- a/tests/php-unit-tests/integration-tests/login-tests/LoginWebPageTest.php +++ b/tests/php-unit-tests/integration-tests/login-tests/LoginWebPageTest.php @@ -111,7 +111,7 @@ class LoginWebPageTest extends ItopDataTestCase $this->assertStringContainsString('iTop login', $sPageContent, 'if itop is configured to force login when no there is no delegated authentication endpoints list, then login should be required.'); } - public function testWithoutDelegatedAuthenticationEndpointsListWithDefaultConfiguration() + public function testWithoutDelegatedAuthenticationEndpointsListRequiresLoginByDefault() { $sPageContent = $this->CallItopUri( "pages/exec.php?exec_module=extension-without-delegated-authentication-endpoints-list&exec_page=src/Controller/File.php", @@ -120,7 +120,24 @@ class LoginWebPageTest extends ItopDataTestCase true ); - $this->assertStringContainsString('Yo', $sPageContent, 'by default (until N°9343) if no delegated authentication endpoints list is defined, not logged in persons should access pages'); + $this->assertStringContainsString('iTop login', $sPageContent, 'by default, login should be required when no delegated authentication endpoints list is defined'); + } + + public function testWithoutDelegatedAuthenticationEndpointsListWithCompatibilityOptOut() + { + @chmod($this->oConfig->GetLoadedFile(), 0770); + $this->oConfig->Set('security.disable_exec_forced_login_for_all_enpoints', true, 'AnythingButEmptyOrUnknownValue'); + $this->oConfig->WriteToFile(); + @chmod($this->oConfig->GetLoadedFile(), 0444); + + $sPageContent = $this->CallItopUri( + "pages/exec.php?exec_module=extension-without-delegated-authentication-endpoints-list&exec_page=src/Controller/File.php", + [], + [], + true + ); + + $this->assertStringContainsString('Yo !', $sPageContent, 'the compatibility opt-out should allow anonymous access when no delegated authentication endpoints list is defined'); } public function testNotInDelegatedAuthenticationEndpointsList()