Details

    • Branch Version/s:
      6.0.x
    • Similar Issues:
      Show 5 results 

      Description

      Before Liferay 5.2.x you could access Message Board feeds from a private page without authentication. Since 5.2.x you must authenticate for accessing such a feed.
      Instead of using HTTP (Basic) Authentication, xou must use the form-based auth.

      That is very annoying, because common feed readers only know to authenticate by using HTTP Authentication. And the is a property in portal.properties where you can set the non auth paths "auth.public.paths". If this property is there and "/message_boards/rss" in included in this property, there should be no authentication required for feeds.

      So what is the point? Either the entries in "auth.public.paths" are respected with no exceptions, or feeds should be accessible by using HTTP (Basic) Authentication, if a feed is from a Message Board in a private community.

        Issue Links

          Activity

          Hide
          Tobias Kaefer added a comment -

          BTW:
          The filters for web.xml that I mentioned, do only work for blogs, message boardd and wikis. They do not give access to the activities portlet. This is because of the structure of the url for activity feeds:
          http://poertal-host:8080/group/<group-name>/forum/-/activities/rss

          You cannot filter for something like this:
          /group/*/forum/-/activities/rss

          So if there will be a solution, it has to deal with these things.

          Show
          Tobias Kaefer added a comment - BTW: The filters for web.xml that I mentioned, do only work for blogs, message boardd and wikis. They do not give access to the activities portlet. This is because of the structure of the url for activity feeds: http://poertal-host:8080/group/ <group-name>/forum/-/activities/rss You cannot filter for something like this: /group/*/forum/-/activities/rss So if there will be a solution, it has to deal with these things.
          Hide
          Christopher Lui added a comment -

          Hi Tobias,

          We're a little confused about the description.

          Could you give us the exact steps you used to reproduce this issue?

          Thanks,
          Chris

          Show
          Christopher Lui added a comment - Hi Tobias, We're a little confused about the description. Could you give us the exact steps you used to reproduce this issue? Thanks, Chris
          Hide
          Tobias Kaefer added a comment -

          Create a community with with private pages.
          Add a Wiki, Blog, Message Board to those sites.
          Add some content (Threads, Wiki Pages etc.).
          Try to access one of the RSS-Feeds from a Feed-Reader other than the browser you are currently logged in to the portal (like Thunderbird RSS-Reader feature).

          You won't be able to read any of those Feeds for content on a private page, since it you will be redirected to a HTML form base authentication.
          That does not work, if you are using a Feed-Reader.

          The filters for the web.xml fix this issue for the Blog, Wiki and Message Board, but it does not fix it for the Activities Portlet, since you cannot create a valid filter, that fits the servlet spec.

          Show
          Tobias Kaefer added a comment - Create a community with with private pages. Add a Wiki, Blog, Message Board to those sites. Add some content (Threads, Wiki Pages etc.). Try to access one of the RSS-Feeds from a Feed-Reader other than the browser you are currently logged in to the portal (like Thunderbird RSS-Reader feature). You won't be able to read any of those Feeds for content on a private page, since it you will be redirected to a HTML form base authentication. That does not work, if you are using a Feed-Reader. The filters for the web.xml fix this issue for the Blog, Wiki and Message Board, but it does not fix it for the Activities Portlet, since you cannot create a valid filter, that fits the servlet spec.
          Hide
          Kristoffer Onias added a comment -

          Hello Tobias,
          I have confirmed that the message boards RSS function fails to work on both 6.0.5 GA and 6.0.x Revision: 70847. Thank you for reporting!

          Show
          Kristoffer Onias added a comment - Hello Tobias, I have confirmed that the message boards RSS function fails to work on both 6.0.5 GA and 6.0.x Revision: 70847. Thank you for reporting!
          Hide
          Raymond Auge added a comment -

          I've committed a new fix to the linked ticket. Please re-open that ticket if the issue re-appears or is not adequately solved.

          Show
          Raymond Auge added a comment - I've committed a new fix to the linked ticket. Please re-open that ticket if the issue re-appears or is not adequately solved.

            People

            • Votes:
              2 Vote for this issue
              Watchers:
              10 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Days since last comment:
                4 years, 6 weeks, 1 day ago

                Development

                  Structure Helper Panel