Compare commits

...

14 Commits

Author SHA1 Message Date
Stephen Abello
87b6b34683 Merge branch 'support/3.2' into support/3.3
# Conflicts:
#	core/oql/expression.class.inc.php
2026-10-01 17:10:51 +02:00
Molkobain
0a4bbfe5a9 🙈 Ensure data/.compilation-symlinks is not commited is deleted 2026-10-01 16:29:57 +02:00
Stephen Abello
31a4e1a0a0 N°10120 - Filtered classes in subqueries produce invalid SQL (#1059)
* N°10120 - Filtered classes in subqueries produce invalid SQL

* Avoid SQL cache to be shared between ids only and full columns queries
2026-10-01 10:44:33 +02:00
Stephen Abello
de74103118 Fix unit test cause by security changes in #1055 2026-10-01 09:35:55 +02:00
Stephen Abello
67c6a0732c Merge branch 'support/3.2' into support/3.3 2026-09-29 10:03:43 +02:00
Stephen Abello
a2a00cb582 N°10075 - Update configuration parameters default value (#1055) 2026-09-29 10:02:57 +02:00
jf-cbd
4e8d34bb23 Merge remote-tracking branch 'origin/support/3.2' into support/3.3 2026-09-28 11:40:24 +02:00
jf-cbd
4d699f79e8 Add unit test for N°9740 2026-09-28 11:30:54 +02:00
Molkobain
4e70886d2a 💬 Update version to 3.3.1 2026-09-27 17:55:49 +02:00
Stephen Abello
c2929ecd33 Merge branch 'support/3.2' into support/3.3 2026-09-25 10:28:55 +02:00
Stephen Abello
873cea1a76 N°9557 - Small improvement to shortcut preferences (#1049)
* N°9557 - Small improvement to shortcut preferences

* Apply code review suggestions
2026-09-25 10:28:05 +02:00
jf-cbd
b7432b9e60 Merge remote-tracking branch 'origin/support/3.2' into support/3.3 2026-09-21 09:50:18 +02:00
jf-cbd
adc2596b4a Issue/9740 fix attachment removal (#1052)
(cherry picked from commit af972313d7)
2026-09-18 15:40:52 +02:00
Denis
16d68fe993 Version 3.3.0 2026-09-15 15:29:07 +02:00
67 changed files with 721 additions and 893 deletions

View File

@@ -110,11 +110,11 @@ gitGraph
commit id: "2025-09-25" tag: "2.7.13"
checkout support/3.2
commit id: "2026-04-27 " tag: "3.2.3"
checkout support/3.2.3
commit id: "2026-05-25 " tag: "3.2.3-1"
commit id: "2026-07-17 " tag: "3.2.3-2"
checkout develop
commit id: "2026-07-23" tag: "3.3.0-beta1"
commit id: "2026-09-15" tag: "3.3.0"
```
To learn more, check the [iTop community versions history on the official wiki](https://www.itophub.io/wiki/page?id=latest:release:start).

1
.gitignore vendored
View File

@@ -33,7 +33,6 @@ tests/*/vendor/*
!/data/index.php
!/data/web.config
!/data/exclude.txt
!/data/.compilation-symlinks
# iTop extensions
/extensions/**

View File

@@ -109,10 +109,18 @@ $('#shortcut_rename_dlg').dialog({
modal: true,
title: '$sDialogTitle',
buttons: [
{ text: "$sOkButtonLabel", click: ShortcutRenameOK},
{ text: "$sCancelButtonLabel", click: function() {
$(this).dialog( "close" ); $(this).remove();
} },
{
text: "$sCancelButtonLabel",
click: function() {
$(this).dialog( "close" ); $(this).remove();
},
'class': 'ibo-button ibo-is-alternative ibo-is-neutral action cancel'
},
{
text: "$sOkButtonLabel",
click: ShortcutRenameOK,
'class': 'ibo-is-regular ibo-is-primary'
},
],
close: function() { $(this).remove(); }
});

View File

@@ -23,7 +23,7 @@ define('ITOP_DESIGN_LATEST_VERSION', '3.3');
* @used-by utils::GetItopVersionWikiSyntax()
* @used-by iTopModulesPhpVersionIntegrationTest
*/
define('ITOP_CORE_VERSION', '3.3.0');
define('ITOP_CORE_VERSION', '3.3.1');
/**
* @var string

View File

@@ -29,7 +29,7 @@ define('ITOP_APPLICATION_SHORT', 'iTop');
*
* @see ITOP_CORE_VERSION to get iTop core version
*/
define('ITOP_VERSION', '3.3.0-dev');
define('ITOP_VERSION', '3.3.1-dev');
define('ITOP_VERSION_NAME', 'Fullmoon');
define('ITOP_REVISION', 'svn');
@@ -1765,8 +1765,8 @@ class Config
'security.disable_joined_classes_filter' => [
'type' => 'bool',
'description' => 'If true, scope filters aren\'t applied to joined classes or union classes not directly listed in the SELECT clause.',
'default' => true,
'value' => true,
'default' => false,
'value' => false,
'source_of_value' => '',
'show_in_conf_sample' => false,
],
@@ -1781,8 +1781,8 @@ class Config
'security.disable_exec_forced_login_for_all_enpoints' => [
'type' => 'bool',
'description' => 'If true, when no delegated authentication module is defined, no login will be forced on modules exec endpoints',
'default' => true,
'value' => true,
'default' => false,
'value' => false,
'source_of_value' => '',
'show_in_conf_sample' => false,
],

View File

@@ -1711,7 +1711,7 @@ class DBObjectSearch extends DBSearch
* @return array|mixed|\SQLObjectQuery|null
* @throws \CoreException
*/
public function GetSQLQueryStructure($aAttToLoad, $bGetCount, $aGroupByExpr = null, $aSelectedClasses = null, $aSelectExpr = null)
public function GetSQLQueryStructure($aAttToLoad, $bGetCount, $aGroupByExpr = null, $aSelectedClasses = null, $aSelectExpr = null, $bSelectOnlyIds = false)
{
// Hide objects that are not visible to the current user
//
@@ -1782,6 +1782,8 @@ class DBObjectSearch extends DBSearch
$aContextData['aSelectExpr'] = $aSelectExpr;
$sRawId .= $bGetCount;
$aContextData['bGetCount'] = $bGetCount;
$sRawId .= 'ids:'.($bSelectOnlyIds ? '1' : '0');
$aContextData['bSelectOnlyIds'] = $bSelectOnlyIds;
if (is_array($aSelectedClasses)) {
$sRawId .= implode(',', $aSelectedClasses); // Unions may alter the list of selected columns
}
@@ -1835,7 +1837,7 @@ class DBObjectSearch extends DBSearch
if (!isset($oSQLQuery)) {
$oKPI = new ExecutionKPI();
$oSQLObjectQueryBuilder = new SQLObjectQueryBuilder($oSearch);
$oSQLQuery = $oSQLObjectQueryBuilder->BuildSQLQueryStruct($aAttToLoad, $bGetCount, $aModifierProperties, $aGroupByExpr, $aSelectedClasses, $aSelectExpr);
$oSQLQuery = $oSQLObjectQueryBuilder->BuildSQLQueryStruct($aAttToLoad, $bGetCount, $aModifierProperties, $aGroupByExpr, $aSelectedClasses, $aSelectExpr, $bSelectOnlyIds);
$oKPI->ComputeStats('BuildSQLQueryStruct', $sOqlQuery);
if (self::$m_bQueryCacheEnabled) {
@@ -1945,7 +1947,7 @@ class DBObjectSearch extends DBSearch
$oSearch = $this;
$aClassesToFilter = $this->GetSelectedClasses();
// Opt-in for joined classes filtering, otherwise only filter the selected class(es)
// Joined classes filtering can be disabled through the configuration.
if (MetaModel::GetConfig()->Get('security.disable_joined_classes_filter') === false) {
$aClassesToFilter = $this->GetJoinedClasses();
}

View File

@@ -921,7 +921,7 @@ abstract class DBSearch
* @internal
*
*/
public function MakeSelectQuery($aOrderBy = [], $aArgs = [], $aAttToLoad = null, $aExtendedDataSpec = null, $iLimitCount = 0, $iLimitStart = 0, $bGetCount = false, $bBeautifulSQL = true)
public function MakeSelectQuery($aOrderBy = [], $aArgs = [], $aAttToLoad = null, $aExtendedDataSpec = null, $iLimitCount = 0, $iLimitStart = 0, $bGetCount = false, $bBeautifulSQL = true, $bSelectOnlyIds = false)
{
// Check the order by specification, and prefix with the class alias
// and make sure that the ordering columns are going to be selected
@@ -962,7 +962,7 @@ abstract class DBSearch
}
}
$oSQLQuery = $this->GetSQLQuery($aOrderBy, $aArgs, $aAttToLoad, $aExtendedDataSpec, $iLimitCount, $iLimitStart, $bGetCount);
$oSQLQuery = $this->GetSQLQuery($aOrderBy, $aArgs, $aAttToLoad, $aExtendedDataSpec, $iLimitCount, $iLimitStart, $bGetCount, null, null, $bSelectOnlyIds);
if ($this->m_bNoContextParameters) {
// Only internal parameters
@@ -1046,7 +1046,7 @@ abstract class DBSearch
* @internal
*
*/
protected function GetSQLQuery($aOrderBy, $aArgs, $aAttToLoad, $aExtendedDataSpec, $iLimitCount, $iLimitStart, $bGetCount, $aGroupByExpr = null, $aSelectExpr = null)
protected function GetSQLQuery($aOrderBy, $aArgs, $aAttToLoad, $aExtendedDataSpec, $iLimitCount, $iLimitStart, $bGetCount, $aGroupByExpr = null, $aSelectExpr = null, $bSelectOnlyIds = false)
{
$oSearch = $this->ApplyDataFilters();
@@ -1068,7 +1068,7 @@ abstract class DBSearch
}
}
$oSQLQuery = $oSearch->GetSQLQueryStructure($aAttToLoad, $bGetCount, $aGroupByExpr, null, $aSelectExpr);
$oSQLQuery = $oSearch->GetSQLQueryStructure($aAttToLoad, $bGetCount, $aGroupByExpr, null, $aSelectExpr, $bSelectOnlyIds);
$oSQLQuery->SetSourceOQL($oSearch->ToOQL());
// Join to an additional table, if required...
@@ -1103,7 +1103,8 @@ abstract class DBSearch
$bGetCount,
$aGroupByExpr = null,
$aSelectedClasses = null,
$aSelectExpr = null
$aSelectExpr = null,
$bSelectOnlyIds = false
);
/**

View File

@@ -527,10 +527,10 @@ class DBUnionSearch extends DBSearch
throw new Exception('MakeUpdateQuery is not implemented for the unions!');
}
public function GetSQLQueryStructure($aAttToLoad, $bGetCount, $aGroupByExpr = null, $aSelectedClasses = null, $aSelectExpr = null)
public function GetSQLQueryStructure($aAttToLoad, $bGetCount, $aGroupByExpr = null, $aSelectedClasses = null, $aSelectExpr = null, $bSelectOnlyIds = false)
{
if (count($this->aSearches) == 1) {
return $this->aSearches[0]->GetSQLQueryStructure($aAttToLoad, $bGetCount, $aGroupByExpr, $aSelectedClasses, $aSelectExpr);
return $this->aSearches[0]->GetSQLQueryStructure($aAttToLoad, $bGetCount, $aGroupByExpr, $aSelectedClasses, $aSelectExpr, $bSelectOnlyIds);
}
$aSQLQueries = [];
@@ -610,7 +610,7 @@ class DBUnionSearch extends DBSearch
}
}
}
$oSubQuery = $oSearch->GetSQLQueryStructure($aQueryAttToLoad, false, $aQueryGroupByExpr, $aSearchSelectedClasses, $aQuerySelectExpr);
$oSubQuery = $oSearch->GetSQLQueryStructure($aQueryAttToLoad, false, $aQueryGroupByExpr, $aSearchSelectedClasses, $aQuerySelectExpr, $bSelectOnlyIds);
if (count($aSearchAliases) > 1) {
// Necessary to make sure that selected columns will match throughout all the queries
// (default order of selected fields depending on the order of JOINS)
@@ -683,7 +683,7 @@ class DBUnionSearch extends DBSearch
return $this;
}
// Opt-in for joined classes filtering, otherwise fallback on DBSearch filtering
// Joined classes filtering can be disabled through the configuration.
if (MetaModel::GetConfig()->Get('security.disable_joined_classes_filter') === true) {
return parent::ApplyDataFilters();
}

File diff suppressed because it is too large Load Diff

View File

@@ -29,13 +29,14 @@ class SQLObjectQueryBuilder
* @param array $aGroupByExpr
* @param array $aSelectedClasses
* @param array $aSelectExpr
* @param bool $bSelectOnlyIds
*
* @return null|SQLObjectQuery
* @throws \CoreException
*/
public function BuildSQLQueryStruct($aAttToLoad, $bGetCount, $aModifierProperties, $aGroupByExpr = null, $aSelectedClasses = null, $aSelectExpr = null)
public function BuildSQLQueryStruct($aAttToLoad, $bGetCount, $aModifierProperties, $aGroupByExpr = null, $aSelectedClasses = null, $aSelectExpr = null, $bSelectOnlyIds = false)
{
if ($bGetCount || !is_null($aGroupByExpr)) {
if ($bGetCount || !is_null($aGroupByExpr) || $bSelectOnlyIds) {
// Avoid adding all the fields for counts or "group by" requests
$aAttToLoad = [];
foreach ($this->oDBObjetSearch->GetSelectedClasses() as $sClassAlias => $sClass) {

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'authent-cas/3.3.0',
'authent-cas/3.3.1',
[
// Identification
//

View File

@@ -27,7 +27,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'authent-external/3.3.0',
'authent-external/3.3.1',
[
// Identification
//

View File

@@ -7,7 +7,7 @@ if (function_exists('ldap_connect')) {
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'authent-ldap/3.3.0',
'authent-ldap/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'authent-local/3.3.0',
'authent-local/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'combodo-backoffice-darkmoon-theme/3.3.0',
'combodo-backoffice-darkmoon-theme/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'combodo-backoffice-fullmoon-high-contrast-theme/3.3.0',
'combodo-backoffice-fullmoon-high-contrast-theme/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'combodo-backoffice-fullmoon-protanopia-deuteranopia-theme/3.3.0',
'combodo-backoffice-fullmoon-protanopia-deuteranopia-theme/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'combodo-backoffice-fullmoon-tritanopia-theme/3.3.0',
'combodo-backoffice-fullmoon-tritanopia-theme/3.3.1',
[
// Identification
//

View File

@@ -11,7 +11,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'combodo-data-feature-removal/3.3.0',
'combodo-data-feature-removal/3.3.1',
[
// Identification
//

View File

@@ -25,7 +25,7 @@
/** @noinspection PhpUnhandledExceptionInspection */
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'combodo-db-tools/3.3.0',
'combodo-db-tools/3.3.1',
[
// Identification
//

View File

@@ -56,7 +56,7 @@ function RenderAttachments(AjaxPage $oPage, $iTransactionId)
try {
require_once APPROOT.'/application/startup.inc.php';
require_once APPROOT.'/application/loginwebpage.class.inc.php';
LoginWebPage::DoLoginEx(null /* any portal */, false);
LoginWebPage::DoLogin(); // No user portal should access this endpoint.
$oPage = new AjaxPage("");
@@ -105,15 +105,6 @@ try {
$oPage->SetData($aResult);
break;
case 'remove':
$iAttachmentId = utils::ReadParam('att_id', '');
$oSearch = DBObjectSearch::FromOQL("SELECT Attachment WHERE id = :id");
$oSet = new DBObjectSet($oSearch, [], ['id' => $iAttachmentId]);
while ($oAttachment = $oSet->Fetch()) {
$oAttachment->DBDelete();
}
break;
case 'refresh_attachments_render':
$sTempId = utils::ReadParam('temp_id', '', false, 'transaction_id');
RenderAttachments($oPage, $sTempId);

View File

@@ -19,7 +19,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-attachments/3.3.0',
'itop-attachments/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-backup/3.3.0',
'itop-backup/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-bridge-cmdb-services/3.3.0',
'itop-bridge-cmdb-services/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-bridge-cmdb-ticket/3.3.0',
'itop-bridge-cmdb-ticket/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-bridge-datacenter-mgmt-services/3.3.0',
'itop-bridge-datacenter-mgmt-services/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-bridge-endusers-devices-services/3.3.0',
'itop-bridge-endusers-devices-services/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-bridge-storage-mgmt-services/3.3.0',
'itop-bridge-storage-mgmt-services/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-bridge-virtualization-mgmt-services/3.3.0',
'itop-bridge-virtualization-mgmt-services/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-bridge-virtualization-storage/3.3.0',
'itop-bridge-virtualization-storage/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-change-mgmt-itil/3.3.0',
'itop-change-mgmt-itil/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-change-mgmt/3.3.0',
'itop-change-mgmt/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-config-mgmt/3.3.0',
'itop-config-mgmt/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-config/3.3.0',
'itop-config/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-container-mgmt/3.3.0',
'itop-container-mgmt/3.3.1',
[
// Identification
//

View File

@@ -25,7 +25,7 @@
/** @noinspection PhpUnhandledExceptionInspection */
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-core-update/3.3.0',
'itop-core-update/3.3.1',
[
// Identification
//

View File

@@ -19,7 +19,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-datacenter-mgmt/3.3.0',
'itop-datacenter-mgmt/3.3.1',
[
// Identification
//

View File

@@ -26,7 +26,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-endusers-devices/3.3.0',
'itop-endusers-devices/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-faq-light/3.3.0',
'itop-faq-light/3.3.1',
[
// Identification
//

View File

@@ -25,7 +25,7 @@
/** @noinspection PhpUnhandledExceptionInspection */
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-files-information/3.3.0',
'itop-files-information/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-flow-map/3.3.0',
'itop-flow-map/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-full-itil/3.3.0',
'itop-full-itil/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-hub-connector/3.3.0',
'itop-hub-connector/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-incident-mgmt-itil/3.3.0',
'itop-incident-mgmt-itil/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-knownerror-mgmt/3.3.0',
'itop-knownerror-mgmt/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-oauth-client/3.3.0',
'itop-oauth-client/3.3.1',
[
// Identification
//

View File

@@ -21,7 +21,7 @@
/** @noinspection PhpUnhandledExceptionInspection */
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-portal-base/3.3.0',
'itop-portal-base/3.3.1',
[
// Identification
'label' => 'Portal Development Library',

View File

@@ -21,7 +21,7 @@
/** @noinspection PhpUnhandledExceptionInspection */
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-portal/3.3.0',
'itop-portal/3.3.1',
[
// Identification
'label' => 'Enhanced Customer Portal',

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-problem-mgmt/3.3.0',
'itop-problem-mgmt/3.3.1',
[
// Identification
//

View File

@@ -19,7 +19,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-profiles-itil/3.3.0',
'itop-profiles-itil/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-request-mgmt-itil/3.3.0',
'itop-request-mgmt-itil/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-request-mgmt/3.3.0',
'itop-request-mgmt/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-service-mgmt-provider/3.3.0',
'itop-service-mgmt-provider/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-service-mgmt/3.3.0',
'itop-service-mgmt/3.3.1',
[
// Identification
//

View File

@@ -19,7 +19,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-sla-computation/3.3.0',
'itop-sla-computation/3.3.1',
[
// Identification
//

View File

@@ -26,7 +26,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-storage-mgmt/3.3.0',
'itop-storage-mgmt/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-structure/3.3.0',
'itop-structure/3.3.1',
[
// Identification
//

View File

@@ -6,7 +6,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-themes-compat/3.3.0',
'itop-themes-compat/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__,
'itop-tickets/3.3.0',
'itop-tickets/3.3.1',
[
// Identification
//

View File

@@ -17,7 +17,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-virtualization-mgmt/3.3.0',
'itop-virtualization-mgmt/3.3.1',
[
// Identification
//

View File

@@ -2,7 +2,7 @@
SetupWebPage::AddModule(
__FILE__, // Path to the current file, all other file names are relative to the directory containing this file
'itop-welcome-itil/3.3.0',
'itop-welcome-itil/3.3.1',
[
// Identification
//

View File

@@ -1,4 +1,4 @@
<?xml version="1.0" encoding="UTF-8"?>
<information>
<version>3.3.0</version>
<version>3.3.1</version>
</information>

View File

@@ -1239,13 +1239,32 @@ JS
$oSearch = new DBObjectSearch('Shortcut');
$aShortcuts = utils::ReadMultipleSelection($oSearch);
$iShortcut = $aShortcuts[0];
$oShortcut = MetaModel::GetObject('Shortcut', $iShortcut);
$oShortcutSearch = new DBObjectSearch('Shortcut');
$oShortcutSearch->AddCondition('user_id', UserRights::GetUserId(), '=');
$oShortcutSearch->AddCondition('id', $iShortcut, '=');
$oShortcutSet = new CMDBObjectSet($oShortcutSearch);
$oShortcut = $oShortcutSet->Fetch();
if ($oShortcut === null) {
throw new SecurityException(Dict::S('UI:ObjectDoesNotExist'));
}
$oShortcut->StartRenameDialog($oPage);
break;
case 'shortcut_rename_go':
$iShortcut = utils::ReadParam('id', 0);
$oShortcut = MetaModel::GetObject('Shortcut', $iShortcut);
$oShortcutSearch = new DBObjectSearch('Shortcut');
$oShortcutSearch->AddCondition('user_id', UserRights::GetUserId(), '=');
$oShortcutSearch->AddCondition('id', $iShortcut, '=');
$oShortcutSet = new CMDBObjectSet($oShortcutSearch);
$oShortcut = $oShortcutSet->Fetch();
if ($oShortcut === null) {
throw new SecurityException(Dict::S('UI:ObjectDoesNotExist'));
}
$sName = utils::ReadParam('attr_name', '', false, 'raw_data');
if (strlen($sName) > 0) {

View File

@@ -244,7 +244,7 @@ JS
);
$oShortcutsToolBar->AddSubBlock($oShortcutsRenameButton);
// - Delete button
$oShortcutsDeleteButton = ButtonUIBlockFactory::MakeForSecondaryAction(
$oShortcutsDeleteButton = ButtonUIBlockFactory::MakeForDestructiveAction(
Dict::S('UI:Button:Delete'),
null,
null,

View File

@@ -111,7 +111,7 @@ class LoginWebPageTest extends ItopDataTestCase
$this->assertStringContainsString('<title>iTop login</title>', $sPageContent, 'if itop is configured to force login when no there is no delegated authentication endpoints list, then login should be required.');
}
public function testWithoutDelegatedAuthenticationEndpointsListWithDefaultConfiguration()
public function testWithoutDelegatedAuthenticationEndpointsListRequiresLoginByDefault()
{
$sPageContent = $this->CallItopUri(
"pages/exec.php?exec_module=extension-without-delegated-authentication-endpoints-list&exec_page=src/Controller/File.php",
@@ -120,7 +120,24 @@ class LoginWebPageTest extends ItopDataTestCase
true
);
$this->assertStringContainsString('Yo', $sPageContent, 'by default (until N°9343) if no delegated authentication endpoints list is defined, not logged in persons should access pages');
$this->assertStringContainsString('<title>iTop login</title>', $sPageContent, 'by default, login should be required when no delegated authentication endpoints list is defined');
}
public function testWithoutDelegatedAuthenticationEndpointsListWithCompatibilityOptOut()
{
@chmod($this->oConfig->GetLoadedFile(), 0770);
$this->oConfig->Set('security.disable_exec_forced_login_for_all_enpoints', true, 'AnythingButEmptyOrUnknownValue');
$this->oConfig->WriteToFile();
@chmod($this->oConfig->GetLoadedFile(), 0444);
$sPageContent = $this->CallItopUri(
"pages/exec.php?exec_module=extension-without-delegated-authentication-endpoints-list&exec_page=src/Controller/File.php",
[],
[],
true
);
$this->assertStringContainsString('Yo !', $sPageContent, 'the compatibility opt-out should allow anonymous access when no delegated authentication endpoints list is defined');
}
public function testNotInDelegatedAuthenticationEndpointsList()

View File

@@ -419,6 +419,7 @@ class UserLocalTest extends ItopDataTestCase
$this->assertInstanceOf(ormLinkSet::class, $oProfilesSet);
$this->assertEquals(0, $oProfilesSet->Count());
MetaModel::GetConfig()->Set('security.hide_administrators', false);
MetaModel::GetConfig()->Set('security.disable_joined_classes_filter', true);
$oProfilesSet = $this->GetAdminUserProfileList();
$this->assertIsObject($oProfilesSet);
$this->assertInstanceOf(ormLinkSet::class, $oProfilesSet);

View File

@@ -0,0 +1,60 @@
<?php
declare(strict_types=1);
namespace Combodo\iTop\Test\UnitTest\Module\ItopAttachment;
use Combodo\iTop\Test\UnitTest\ItopDataTestCase;
class AttachmentAjaxEndpointTest extends ItopDataTestCase
{
public const USE_TRANSACTION = false;
private const AUTHENTICATION_PASSWORD = 'tagada-Secret,007';
protected function setUp(): void
{
parent::setUp();
$this->BackupConfiguration();
$this->AddLoginModeAndSaveConfiguration('url');
}
/**
* @dataProvider AjaxEndpointAccessProvider
*/
public function testAjaxEndpointAccess(string $sProfile, int $iExpectedHttpCode): void
{
$sLogin = 'user-'.uniqid();
$this->CreateUser($sLogin, self::$aURP_Profiles[$sProfile], self::AUTHENTICATION_PASSWORD);
$iHttpCode = $this->CallAttachmentEndpointAs($sLogin);
$this->assertSame($iExpectedHttpCode, $iHttpCode);
}
public function AjaxEndpointAccessProvider(): array
{
return [
'console user' => ['Service Desk Agent', 200],
'portal user' => ['Portal user', 302], // redirect to portal
];
}
private function CallAttachmentEndpointAs(string $sLogin): int
{
$this->CallItopUri(
'env-production/itop-attachments/ajax.itop-attachment.php?operation=add&'.http_build_query([
'auth_user' => $sLogin,
'auth_pwd' => self::AUTHENTICATION_PASSWORD,
]),
[],
[
CURLOPT_HTTPHEADER => ['X-Combodo-Ajax:1'],
CURLOPT_POST => 0,
],
true
);
return $this->aLastCurlGetInfo['http_code'];
}
}