Details
-
Improvement
-
Status: Closed
-
High
-
Resolution: Fixed
-
None
-
None
Description
Most likely this needs
1) urls for embedded resources start with something like /binaries/_cmsinternal/ etc
2) _cmsinternal should trigger a security check
3) a preview user should be used in the binaries servlet for _cmsinternal
4) resources starting with _cmsinternal should be excluded for caching (also add pragma = no-cache, expiers, etc headers)
Attachments
Issue Links
- includes
-
HSTTWO-3146 Make sure the binaries servlet uses the jcr session from the HstRequestContext
- Closed
- relates to
-
CMS-15452 Preview links are not being generated for resources
- Open