Sitemap.xml lists restricted resources

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

Sitemap.xml lists restricted resources

jondoig

Hi devs

The sitemap.xml file used by Google and other search engines should only list publicly accessible resources. Instead it lists all resources regardless of the permissions set in Geonode.

E.g. demo.geonode.org/sitemap.xml lists three restricted layers not visible in demo.geonode.org/api/layers:

I’ve raised this as issue #3190.

 

Regards

Jonathan


_______________________________________________
geonode-devel mailing list
[hidden email]
https://lists.osgeo.org/mailman/listinfo/geonode-devel
Reply | Threaded
Open this post in threaded view
|

Re: Sitemap.xml lists restricted resources

jondoig

Hi Devs

 

Is anyone able to help with this security issue #3190?

 

Also the related issue #1726, Metadata for private layers should be consistent with layer permissions.

 

Have these been addressed in security improvements since 2.4?

 

Regards

Jonathan

 

From: geonode-devel [mailto:[hidden email]] On Behalf Of Jonathan Doig
Sent: Wednesday, 2 August 2017 1:40 PM
To: geonode-devel <[hidden email]>
Subject: [GeoNode-devel] Sitemap.xml lists restricted resources

 

Hi devs

The sitemap.xml file used by Google and other search engines should only list publicly accessible resources. Instead it lists all resources regardless of the permissions set in Geonode.

E.g. demo.geonode.org/sitemap.xml lists three restricted layers not visible in demo.geonode.org/api/layers:

I’ve raised this as issue #3190.

 

Regards

Jonathan


_______________________________________________
geonode-devel mailing list
[hidden email]
https://lists.osgeo.org/mailman/listinfo/geonode-devel