Support

Admin Tools

#13374 Just a suggestion re default settings in WAF to permit "email a friend"

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Saturday, 25 August 2012 02:52 CDT

Missy
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? Yes
Have I searched the tickets before posting? Yes
Have I read the documentation before posting (which pages?)? Yes
Joomla! version: 2.5.6
PHP version: 5.3.13
MySQL version: 5.1.61-log
Host: (optional, but it helps us help you)
Admin Tools version: 2.3.2

Description of my issue:

This is not an issue, but only a suggestion. I had a problem with sending an email to a friend from the email icon at the top of my articles - it triggered the firewall's '"template=" in url' exception.

I found your recommendation in this thread here and have fixed the problem.

I know the answer was in the documentation, but for dumbies like me, it's a big ask to plough through and digest the implictions of every single setting in the configuration when you first install. Some things get missed and forgotten.

I am wondering would it be reasonable to ask you to have the system default for "Allow site templates" set to yes in the WAF configuration? - You're the experts, and I'm sure you have your reasons for setting it to No, so I leave this in your capable hands.

Thanks again for the great support in the forums, and the superb product.

nicholas
Akeeba Staff
Manager
This is an interesting question. I have thought a lot about it before defining the default option for Admin Tools. The email to a friend feature is used very infrequently. Many site owners are happy to disable it without a second thought. Enabling the site template option opens up the a loophole. It works for all site templates, even those which are not published. This may allow some people to play tricks on your side and find out information that they should not have access to. Unless you have no other choice, I recommend not using that option. This is why it is disabled by default.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Missy
I appreciate your genuine concerns for security. Yet it is surprising to hear that the email to a friend feature is used very infrequently. It is an option in K2 as well as Joomla articles. I would have expected web developers to be using every means possible to increase social interactivity. Especially if they are publishing expert articles of high quality. I went to have a look at www.alistapart.com to see what they are doing. At the bottom of their articles, they have icons for sharing via Facebook, Del.icio.us and Twitter, but no email-a-friend. Is email-a-friend becoming old hat? Is that because emailing is becoming a less popular means of communication particularly between young people?

I can't help but think the ideal is to have all sharing options available for users, including email a friend. (Many of the Baby Boomer generation are more accustomed to, and may at times prefer emailing as opposed to other online social forms of sharing; and the Baby Boomer generation still have the dominant numbers.) So the question arises, would it be possible in Admin Tools to be able to enable site template options only for the default or published template, and would that be a safe option? Of course, even if it is possible, I can anticipate that you are not likely to invest much time and effort into securing a feature that you say is not used much.

Still, it is an interesting question with interesting answers. Thank you for taking the time and effort to respond.

nicholas
Akeeba Staff
Manager
Sending e-mail to a friend is becoming obsolete due to its narrow scope. Usually you want to share an article with dozens of people. You'd have to open your email or address book programme, find the email addresses of these twelve people, then go through the near-60-seconds-long e-mail to a friend chore for each one of them. Or you can click on a Facebook "Like" button and 30 seconds later all your friends –including the 12 people you had in mind all along– can see the article you liked. As I am writing these words my friend is sharing an article about how to best roast a stake. My iPhone is giving me a heads up and I don't even have to stop typing this reply. Efficiency at its maximum.

Now, back to the security stuff:
would it be possible in Admin Tools to be able to enable site template options only for the default or published template, and would that be a safe option?
It would be... if only all template developers decided to implement the email link in the same way. Some templates use themselves as the target. Some other templates use beez2, beez5 or atomic. The superset of all these preferences is the "Allow site templates" option as it's currently being implemented :)

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!