The Shoplift bug has had an impact. Magento now seems to be paying more attention to security problems and providing patches more frequently. That is a good thing. As always, the patch announcement arrived at an inconvenient time by German standards, at around 7 p.m. For developers working at agencies, this always means that all customer systems have to be patched promptly the following day (customers with support contracts taking priority, of course).
Every now and then (depending on the size of the patch), this can also lead to problems in customer systems. If the operation of the shop is not directly affected, though, I think security should take priority: roll out the patch first, and then fix the ailments the patch brings to the system afterward.
What should you watch out for with patch SUPEE-6285?
Admin controllers
Controller actions are now checked case-sensitively. In the Adminhtml controllers, the _isAllowed method, which is responsible for checking permissions, has been introduced in many places.
This change is also interesting:
diff --git a/www/app/code/core/Mage/Adminhtml/Controller/Action.php b/www/app/code/core/Mage/Adminhtml/Controller/Action.php index aad9b74..d630e35 100644 --- a/www/app/code/core/Mage/Adminhtml/Controller/Action.php +++ b/www/app/code/core/Mage/Adminhtml/Controller/Action.php @@ -71,7 +71,7 @@ class Mage_Adminhtml_Controller_Action extends Mage_Core_Controller_Varien_Actio protected function _isAllowed() { - return true; + return Mage::getSingleton('admin/session')->isAllowed('admin'); }
What does this mean? If you had not explicitly defined permissions before, any logged-in user in the admin area could use your controller. That was certainly not a particularly defensive default from Magento, and it has now been adjusted. From now on, controllers without their own _isAllowed method can only be accessed by users with admin rights. I think that is correct. The logic has also been included this way in the development version of Magento 2 for a while.
So if you get a 404 error for certain sections in the admin area, you should look at the relevant controller and check whether the _isAllowed method is missing. Ideally, define your own ACL resource and check it in the controller. Afterward, all roles that should have access to the resource need to be adjusted accordingly in permission management (check the box).
Frontend templates
For this, it is best to look at the changed files. For example, frontend templates were revised because escaping was not always done properly there.
The following files are affected:
app/design/frontend/base/default/template/checkout/cart.phtml app/design/frontend/base/default/template/checkout/cart/noItems.phtml app/design/frontend/base/default/template/checkout/onepage/failure.phtml app/design/frontend/base/default/template/rss/order/details.phtml app/design/frontend/base/default/template/wishlist/email/rss.phtml app/design/frontend/rwd/default/template/checkout/cart.phtml EE -> app/design/frontend/enterprise/default/template/checkout/cart.phtml
Directory permissions
When the log directories "var/log" and "var/reports" are created, the default permissions are now "775" rather than "777". A few .htaccess files for the Apache web server were also added. These configurations do not apply to Nginx, for example, and have to be accounted for there through an appropriate setting. This also affects Apache servers that do not process .htaccess files.
Downloader
The downloader was also adjusted in a few places. I recommend removing the downloader from every production environment, since there is no reason to equip a production system that, for example, is deployed automatically with an option for manual module installation.
However, you will then run into problems applying the patch, which even expects a downloader already modified by a previous patch. In this case, we simply adjusted the patch's ".sh" file and removed all downloader-related lines.
Conclusion
So we can see that there are quite a few things to bear in mind when applying security patches. Just install it and you are done.... that is not how it works. Customers should therefore not be surprised if the invoice shows more than just 10 minutes.