Closed lucaa closed 3 years ago
Now, I asked the XWiki platform team and apparently the "rule" from their point of view, is something like this:
I would say that in this case we could explore option no 2 (but it depends on what the vote service is actually doing) and definitely option no 3 otherwise.
This being said, maybe all applications should be audited for this risk.
Whatever the choice, "Hello world" should definitely be replaced with something more expressive. Also, since hello world seems to be part of some error handling for the vote service, maybe it could also endup displayed in other situations, not only this one, so we definitely need to replace it with something as explicit as possible wrt the cause of the error.
FTR, "Hello world" is the text displayed when you don't specify any notification message. So we just need to provide a proper error message in this case.
Regarding the programming rights issue, we definitely need to investigate why we need it, and if it's really needed the we need to update the documentation and:
A proper error message will be displayed instead of the "Hello world". For the root problem with the need of programming rights I opened a new issue #46
Steps to reproduce:
Expected result:
Actual result:
When checking the console, the ajax call sent for the vote returns with the following response: