Uploaded image for project: 'Hippo Archetype'
  1. Hippo Archetype
  2. ARCHE-546

Use hard-coded UUID for base documents and gallery folder?

    XMLWordPrintable

    Details

    • Type: Question
    • Status: Closed
    • Priority: Normal
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 12.0.1
    • Labels:
      None
    • Similar issues:
    • Story Points:
      0.5
    • Epic Link:
    • Processed by team:
      Platform
    • Sprint:
      Platform162: Pre-GA2

      Description

      During the implementation of ARCHE-541, we discussed if the archetype's content sources for bootstrapping /content/documents/<project-name> and /content/gallery/<project-name> should include a UUID or not.

      If they have a UUID, the UUID of these nodes will be identical for all Hippo projects (unless a developer changes them manually), potentially constituting a security vulnerability.

      If they don't have a UUID, a UUID will be generated on bootstrapping, and auto-export will add that UUID to the content sources, so they will still be the same across all environments into which the project is deployed (which is a much smaller, probably negligible security vulnerability). Also, if the original, clean project is put under VCS, auto-export adding the UUID will show up as a local - probably unexpected - source code change.

      Currently, the UUID is there.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              tjeger Tobias Jeger
            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: