Issue 128453 - New security warning blocks useful functions
Summary: New security warning blocks useful functions
Status: CLOSED FIXED
Alias: None
Product: General
Classification: Code
Component: ui (show other issues)
Version: 4.1.10
Hardware: PC All
: P4 Normal (vote)
Target Milestone: 4.1.11
Assignee: AOO issues mailing list
QA Contact:
URL:
Keywords:
: 128454 (view as issue list)
Depends on:
Blocks:
 
Reported: 2021-05-12 15:45 UTC by Peter Pratten
Modified: 2021-07-02 18:39 UTC (History)
5 users (show)

See Also:
Issue Type: DEFECT
Latest Confirmation in: ---
Developer Difficulty: ---


Attachments
Test case: links to current document. (25.68 KB, application/vnd.oasis.opendocument.spreadsheet)
2021-05-13 19:25 UTC, Arrigo Marchiori
no flags Details

Note You need to log in before you can comment on or make changes to this issue.
Description Peter Pratten 2021-05-12 15:45:47 UTC
This relates to issue 22228. I have tried everything I can find from the option specified under that issue but cannot clear the message.
I use a hyperlink to open a local file during a presentation. Worked OK at v 4.1.9 but at 4.1.10 I get the security warning. I have tried setting the folder as a trusted location. I have also tried setting the security level to low. The showing of the warning at every occurrence makes the presentation unacceptable. If I can't get rid of it I'll have to return to 4.1.9.
Comment 1 Arrigo Marchiori 2021-05-13 05:37:46 UTC
Thank you for reporting this problem.

I took the liberty to rename your report, in order to collect here all reports of wrong behavior of the new warning policy on links.

Could you post here an example link that should be working for you?
You obfuscate paths for privacy (such as C:\xxx\yyy.ods or /home/user/aaa.ods) but it would be useful for us to see its form.
Comment 2 Arrigo Marchiori 2021-05-13 05:38:16 UTC
Another problem was reported on the Italian forum:
https://forum.openoffice.org/it/forum/viewtopic.php?f=9&p=63945#p63904

Links to the same documents (i.e. starting with "#") trigger the warning, and should not.
Comment 3 Peter Pratten 2021-05-13 11:26:57 UTC
Thanks for rewording the problem. I see there are wider effects.
The link I use is "O:\Music\Playlists\1 - Prelude.wpl". O: has been defined as the OneDrive. Answering the security with "Yes" plays music defined, but showing the message is a distraction.
Comment 4 Carl Marcum 2021-05-13 13:14:30 UTC
One from dev@ list is using the .uno:XXX type commands in hyperlinks.
THere are examples on the forums like this one [1] for Reload and Close.

[1] https://forum.openoffice.org/en/forum/viewtopic.php?f=9&t=100502&p=483689&hilit=.uno%3AReload#p483689
Comment 5 Arrigo Marchiori 2021-05-13 19:25:19 UTC
Created attachment 87025 [details]
Test case: links to current document.

This is a test case that was reported to the Italian forum (comment #2).

Open it ignoring the macros and click the purple button "Ritorna". It points to "#Base.B19" where "Base" is another sheet in the same document.

Current result: the warning is displayed.

Expected outcome: the link should be followed without warnings.
Comment 6 Matthias Seidel 2021-05-29 13:33:30 UTC
*** Issue 128454 has been marked as a duplicate of this issue. ***
Comment 8 Matthias Seidel 2021-06-13 22:57:38 UTC
(In reply to Peter Pratten from comment #3)
> Thanks for rewording the problem. I see there are wider effects.
> The link I use is "O:\Music\Playlists\1 - Prelude.wpl". O: has been defined
> as the OneDrive. Answering the security with "Yes" plays music defined, but
> showing the message is a distraction.

Hi Peter,

Since I think you use Windows, maybe you would like to do a test with:

https://home.apache.org/~mseidel/AOO-builds/AOO-4111-Test/Full%20Installation/

It would be interesting if .wpl is opened without warning now.
Comment 9 Peter Pratten 2021-06-14 10:38:38 UTC
As suggested I installed the test version of 4.1.11 but I still got the warning message.
Comment 10 Arrigo Marchiori 2021-06-14 13:31:29 UTC
Hi Peter,

you are totally right! The "WPL" extension is not (yet) listed among the "safe" ones.

Reopening to be coherent with the current situation.
Comment 11 Matthias Seidel 2021-06-24 10:20:54 UTC
(In reply to Peter Pratten from comment #9)
> As suggested I installed the test version of 4.1.11 but I still got the
> warning message.

Hi, can you please try:

https://home.apache.org/~mseidel/AOO-builds/AOO-4111-Test/Full%20Installation/Apache_OpenOffice_4.1.11_Win_x86_install_en-US_f2fa887bab.exe
Comment 12 Peter Pratten 2021-06-24 22:56:34 UTC
I have tried the new test version of 4.1.11 (comment #11) but still got the error message. While testing I got a NortonLivelock error 3048,3 but don't know if it is related.
I tried using the Help button which brought up the Security Warning page. The instructions at the top of the help page left me lost, so I picked the "Always trust macros from this source" which showed I had already marked the folder containing the .wpl files as a Trusted file location.
Comment 13 Matthias Seidel 2021-06-24 23:17:33 UTC
Are you sure you installed the new version?

I have no problem opening a hyperlink to a .wpl file. No message box.
This is on Windows 10.
Comment 14 Peter Pratten 2021-06-25 19:57:09 UTC
I am on the test version of 4.1.11. I have found the problem. To provide flexibility I used a shortcut to the .wpl file, which, on rare occasions, I could change to a .m4a file more easily than remaking the hyperlink (can't find easy way to edit it). Normally all commands to a shortcut pass straight through (except rename and delete). This appears not to be the case. By removing the shortcut it works for the .wpl files. 
However the .m4a files are not in the WMP so I tried Slide Show > Interactive > Play Sound as an alternative but that didn't work.
Comment 15 Peter Pratten 2021-06-25 20:24:19 UTC
Is it necessary to revert to 4.1.10 until final release? Continuing to work inserting a text file causes AOO to crash.
Comment 16 Matthias Seidel 2021-06-25 20:27:22 UTC
I don't know why that should happen...

If it does please open another ticket.
Comment 17 Matthias Seidel 2021-06-26 10:51:59 UTC
Next Test build for Windows:

https://home.apache.org/~mseidel/AOO-builds/AOO-4111-Test/Full%20Installation/Apache_OpenOffice_4.1.11_Win_x86_install_en-US_06eb56818a.exe

This one supersedes the lat Test build.
Comment 18 Arrigo Marchiori 2021-06-26 11:46:38 UTC
(In reply to Matthias Seidel from comment #17)
> Next Test build for Windows:
> 
> https://home.apache.org/~mseidel/AOO-builds/AOO-4111-Test/
> Full%20Installation/Apache_OpenOffice_4.1.11_Win_x86_install_en-
> US_06eb56818a.exe
> 
> This one supersedes the lat Test build.

Does it already contain the ".m4a" addition?

If so, could Peter please test it so we can close this bug?

Thank you in advance to both of you.
Comment 19 Matthias Seidel 2021-06-26 11:56:31 UTC
I did the build after your last commit yesterday, so m4a should be included.

However, there never was a problem with hyperlinks to m4a. I just cross-checked with 4.2.0.
Comment 20 Arrigo Marchiori 2021-06-26 12:18:00 UTC
(In reply to Matthias Seidel from comment #19)
> I did the build after your last commit yesterday, so m4a should be included.
> 
> However, there never was a problem with hyperlinks to m4a. I just
> cross-checked with 4.2.0.

Ok, then we'll wait for Peter's confirmation.

In the meantime, a Linux build is available here:
https://home.apache.org/~ardovm/openoffice/bug128453/2021-06-26/
Comment 21 Peter Pratten 2021-06-26 21:16:46 UTC
Good news on this issue. The mp4 files do work. My comment about it was misleading. For copyright reason I cannot have certain mp4 files in my Windows Media Player but can play them on certain occasions but have to find another way to do this, hence the shortcuts. In the last line of comment #14 I said "However the .m4a files are not in the WMP so I tried Slide Show > Interactive > Play Sound as an alternative but that didn't work." Should it?

Another piece of good news is that this 4.1.11-DEV file does not crash text files (issue #128464).
Comment 22 Matthias Seidel 2021-06-29 14:20:12 UTC
(In reply to Peter Pratten from comment #14)
> However the .m4a files are not in the WMP so I tried Slide Show >
> Interactive > Play Sound as an alternative but that didn't work.

Works for me...
Comment 23 Matthias Seidel 2021-06-29 14:21:02 UTC
I think we can now close the issue and merge the code into the official branches.
Comment 24 Peter Pratten 2021-06-29 15:34:26 UTC
(In reply to Matthias Seidel from comment #22)
> (In reply to Peter Pratten from comment #14)
> > However the .m4a files are not in the WMP so I tried Slide Show >
> > Interactive > Play Sound as an alternative but that didn't work.
> 
> Works for me...

I tried a few files. The first worked but the others failed. I'm trying to find what is different.
Comment 25 Arrigo Marchiori 2021-06-30 07:29:09 UTC
(In reply to Peter Pratten from comment #24)
> I tried a few files. The first worked but the others failed. I'm trying to
> find what is different.

Please allow me to state the obvious:

 1- if the "failure" consists of the warning dialog appearing, then the files you are opening may have a different extension? We may add them as well to the supported list if they are worth.

 2- if the "failure" is different, then it may not be related to this bug?

Off-topic: I should have better replied yesterday so I could wish you a happy name day :-)
Comment 26 Peter Pratten 2021-06-30 11:46:12 UTC
(In reply to Arrigo Marchiori from comment #25)
> (In reply to Peter Pratten from comment #24)
> > I tried a few files. The first worked but the others failed. I'm trying to
> > find what is different.
> 
> Please allow me to state the obvious:
> 
>  1- if the "failure" consists of the warning dialog appearing, then the
> files you are opening may have a different extension? We may add them as
> well to the supported list if they are worth.
No, "failure" did not mean the warning message. This issues is complete.
> 
>  2- if the "failure" is different, then it may not be related to this bug?
I was trying to establish if I have another bug to report or it was a misunderstanding of what should happen.
> 
> Off-topic: I should have better replied yesterday so I could wish you a
> happy name day :-)
Had to research this, thanks.
Comment 27 Arrigo Marchiori 2021-07-02 18:39:40 UTC
Fix committed to the main branches.

AOO41X: 044ca5aa9b607be6c884da670b2ed585c945d324
AOO42X: b90d22affa19ca465c9195e0cb837c5076cd1a29
trunk: a7138917ac0a2d9d5d1a8295d54cb3ddaca351ae