Skip Navigation

[Resolved] Hard coded js library references

This support ticket is created 6 years, 3 months ago. There's a good chance that you are reading advice that it now obsolete.

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Sun Mon Tue Wed Thu Fri Sat
- 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 -
- 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 -

Supporter timezone: Asia/Kolkata (GMT+05:30)

Tagged: 

This topic contains 5 replies, has 2 voices.

Last updated by triD 5 years, 2 months ago.

Assisted by: Minesh.

Author
Posts
#1084893

Hi there,
I noticed a problem throughout the Types3.0 plugin, where i believe link references as well as inclusion of necessary js files for the core plugin in the admin are hard coded to expect the admin url to always be: /wp-admin/

This is problematic for users who are masking their admin dashboard by using plugins, such as "WP Hide & Security Enhancer", where we can rewrite the admin URL to anything other than the default. For example, my admin url is /not-default-admin/

The hardcoded references in this new version of Types causes links to not work, and most notably, the Custom Fields page (admin.php?page=types-custom-fields) doesnt render because the urls to the default locations for the js files are blocked. You can download the plugin above to test if you like, it is free.

For now, the workaround, is to not block default urls (ie: /wp-admin, /wp-content/paths/to/plugin), but this creates a security hole for sites trying to block access to default paths. Hope this makes sense, thanks.

T

#1087354

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

Hello. Thank you for contacting the Toolset support.

Well - please allow me to consult with our Devs and check what we can do here or is there a way we can fix this for you.

I will get in touch with you as soon as I know more.

#1087424

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

I've reported this issue to our Devs and they are checking what they can do here.

I'll get in touch with you with updates as soon as I know more.

#1089691

Thank you. I should also add that the hardcoded urls are likely also with paths referencing /wp-includes/* as well. Not just admin and content.

#1090184

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

Ok thank you. I shared the information to our Devs. Please hold on for further updates.

#1349623

My issue is resolved now. Thank you!