Documentation: ContentSync plugin
Security
ContentSync brings content from one site into another. The articles are written by other people, on a site you may not manage yourself. So the plugin does not simply trust what it receives. Everything in this article is in both the free and the PRO edition.
Article HTML is filtered
An article can contain more than text. Somebody who can edit articles on the source site could put a script in one, and without a filter that script would run on your site, for your visitors and for you as an administrator.
With Filter Article HTML on, which is the default, ContentSync removes scripting from the article before it is stored: script tags, frames, embedded objects, forms and the attributes that run code. Normal text, images, links, tables and layout stay as they are.
The same filter is applied to textarea and editor custom fields.
Only switch this off when you fully control the source site and everyone who writes there, and when your articles really need something the filter removes. The log reminds you on every run that it is off.
Files are checked before they are written
A file that is downloaded from the source ends up on your web server. That is the place where a wrong file does the most damage, so every file goes through these checks:
- Only known types. Images, and in PRO a fixed list of document, audio and video types. Nothing that a web server runs as a program, and no SVG.
- The content has to match the name. A file that calls itself a JPG has to be a JPG.
- No PHP code. A file that contains PHP is refused, whatever it calls itself.
- Only inside the media folders. A path that tries to climb out of them is refused.
- A size limit. A file that is too large is skipped.
These checks cannot be switched off. A file that fails is skipped, and the log says why. The article itself is still copied.
Access levels are never guessed open
An access level decides who may read an article. Its number is different on every site, so copying the number could show a members-only article to everyone.
ContentSync only carries over the levels Joomla installs itself, which are the same everywhere. For a level you created yourself that is not mapped, it uses the most restrictive level of your site, or skips the article. It never picks a level that visitors can see. See Categories, tags, authors and access levels.
The connection
Verify SSL Certificate is on by default. It makes sure the target site is really talking to your source site and not to something in between.
Only switch it off on a local or staging network you trust. With verification off, someone on the network path could pretend to be the source and feed content into your site. The log reminds you on every run.
Use an https:// address for the source site. The API token travels with every request.
The API token
- The token is a password for the source site. Treat it like one.
- Make a separate user on the source for the sync. Then you can switch the sync off by disabling that user or its token, without touching anyone else.
- The token is stored in the task on the target site. Everyone who may edit scheduled tasks there can see it.
- The token is not written to the log.
Who can start a run
A run is started by the Joomla Task Scheduler. With the scheduler's Lazy Scheduler on, which is the Joomla default, a visit to your site can trigger a task that is due. That is normal Joomla behaviour and nothing a visitor can steer: they cannot choose the source, the settings or the moment.
Found something?
If you think you found a security problem in ContentSync, please tell us through the contact page before you make it public.