Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Apply Smarty Security Policy and replace usage of {crmAPI} in affected templates #51

Open
TychoSchottelius opened this issue Feb 12, 2025 · 0 comments · May be fixed by #53 or #52
Open

Apply Smarty Security Policy and replace usage of {crmAPI} in affected templates #51

TychoSchottelius opened this issue Feb 12, 2025 · 0 comments · May be fixed by #53 or #52
Labels
bug status:needs review Code needs review and testing
Milestone

Comments

@TychoSchottelius
Copy link

As a result of our scans regarding the use of crmAPI, there is on template left using this as an example-template:
/examples/de_greeting_api-queries.tpl

The extension's utility method for rendering Smarty templates does not apply the Smarty User Content Policy introduced with CiviCRM 5.74.4 and 5.69.6
From my perspective it is sufficient to delete this example at all. It would probably be more sustainable to give users an example of querying correctly without using crmAPI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment