When cloning databases from live to test sites, it is sensible to protect the live SF instance by overriding the "salesforce_endpoint" variable in settings.php. Unfortunately, this is inadequate to prevent a cloned site from connecting to the live SF instance, because the request for the Api endpoint doesn't actually us the endpoint variable. It instead uses the "salesforce_identity" struct variable. This can be cloned and re-used, producing undesirable corruption of live data from test sites.

Accessing the salesforce_identity variable should be shielded by validation against the current salesforce_endpoint.

Comments

gcb created an issue. See original summary.

gcb’s picture

gcb’s picture

Improved version to avoid edge case where update runs twice and actually CAUSES the issue we're trying to solve.

gcb’s picture

Improved version that does not require an (unreliable) update or extra data to be stored in the identity variable.

gcb’s picture

gcb’s picture

StatusFileSize
new945 bytes

Previous version was a little too picky as it includes the path for the allowed endpoint, which means a trailing slash (harmless in the config) can break the connection.

This version is more explicit and avoids this problem.

  • gcb committed 7eb6c7e on 7.x-3.x
    Issue #2900041 by gcb: Validate salesforce_endpoint when accessing...
gcb’s picture

Status: Active » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.

mariacha1’s picture

Version: 7.x-3.x-dev » 8.x-3.x-dev
Status: Closed (fixed) » Patch (to be ported)

I'm going to re-open so we can get the same functionality into D8. I'll add a patch back shortly.

mariacha1’s picture

Assigned: Unassigned » mariacha1

  • aaronbauman committed 321c1c4 on 8.x-3.x
    Issue #2900041 by aaronbauman, gcb, mariacha1: Validate...
aaronbauman’s picture

Status: Patch (to be ported) » Fixed

Committed to 8.x-3.x

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.