Wagtail is an open source content management system built on Django
 
 
 
 
 
Go to file
Andy Chosak d1830c0909 prevent users from navigating privileged pages
This change prevents non-admins from navigating around the Wagtail page
tree for pages that lie outside of their explorable root. Currently,
non-admins can hit any page in the tree using a URL like

/admin/pages/123/

even if they don't have any permissions over that page or its part of
the page tree.

This change adds a (temporary) redirect to requests like this, so that
users may not navigate to parts of the tree that lie outside outside of
their explorable site root, as determined by the page privileges they
have. If they try to hit a URL like the one above, they get redirected
to their explorable site root navigation page instead.

Relevant unit tests have been modified to incorporate this change.
2018-04-13 16:47:54 +01:00
.github Mention cross-browser testing in PR template 2018-02-14 17:11:59 +02:00
.tx Renamed wagtail.contrib.wagtailstyleguide to wagtail.contrib.styleguide 2017-11-26 22:43:47 +00:00
client Improve error display cross-browsers, and add translatable string 2018-04-02 19:05:02 +03:00
docs prevent users from navigating privileged pages 2018-04-13 16:47:54 +01:00
etc Fixed spelling error in uwsgi.conf.sample 2017-11-27 13:08:42 +01:00
gulpfile.js Update autoprefixer list on browser support 2018-01-17 21:48:17 +02:00
scripts Removed __future__ imports 2017-11-27 02:18:30 +00:00
wagtail prevent users from navigating privileged pages 2018-04-13 16:47:54 +01:00
.coveragerc Update .coveragerc 2015-12-23 00:09:44 +01:00
.editorconfig Fix whitespace errors in docs 2016-11-28 13:41:35 +00:00
.eslintignore Updated paths in .eslintignore 2017-12-04 22:51:38 +00:00
.eslintrc Update explorer for latest scope, UI, with tests 2017-05-13 23:53:10 +03:00
.gitignore Add pytest cache directories to gitignore 2018-04-08 06:58:19 +02:00
.nvmrc Replace references to Node versions 2017-08-11 15:40:43 +01:00
.stylelintrc.yaml Ignore build folder for CSS linting () 2018-02-10 01:39:44 +02:00
.travis.yml Add Codecov integration to CircleCI to track JS test coverage, with separate flags () 2018-03-06 20:19:37 +02:00
CHANGELOG.txt prevent users from navigating privileged pages 2018-04-13 16:47:54 +01:00
CODE_OF_CONDUCT.md Add Contributor Covenant 2016-02-03 15:47:50 +00:00
CONTRIBUTING.md Revise link to issues for contributing () 2017-12-20 14:07:09 +02:00
CONTRIBUTORS.rst Fixed -- Fixed background color in docs css. 2018-04-12 10:55:24 +02:00
LICENSE Make license perpetual 2017-10-27 09:55:03 +01:00
MANIFEST.in Improvements to MANIFEST.IN 2016-03-09 14:30:25 +00:00
Makefile Fixes - replaces scss-lint with stylelint 2017-08-26 16:39:45 +03:00
README.rst Update test coverage link from coveralls to codecov. Fix 2017-12-20 14:11:40 +02:00
appveyor.yml Remove unsupported environments from appveyor config 2017-10-13 12:27:09 +01:00
circle.yml Add Codecov integration to CircleCI to track JS test coverage, with separate flags () 2018-03-06 20:19:37 +02:00
codecov.yml Disable codecov's require_ci_to_pass mode 2017-06-30 22:59:28 +01:00
conftest.py Removed __future__ imports 2017-11-27 02:18:30 +00:00
package-lock.json Upgrade Draftail to v0.17.1. () 2018-03-27 22:33:25 +02:00
package.json Upgrade Draftail to v0.17.1. () 2018-03-27 22:33:25 +02:00
runtests.py Removed __future__ imports 2017-11-27 02:18:30 +00:00
setup.cfg Use tool:pytest in setup.cfg to fix warning message when running pytest 2018-04-08 06:57:43 +02:00
setup.py Allow html5lib 1.x. Fixes 2018-04-12 11:56:50 +01:00
tox.ini Merge branch 'master' into search-query-api 2018-01-03 18:36:57 +01:00

README.rst

.. image:: https://api.travis-ci.org/wagtail/wagtail.svg?branch=master
    :target: https://travis-ci.org/wagtail/wagtail
.. image:: https://img.shields.io/pypi/l/wagtail.svg
    :target: https://pypi.python.org/pypi/wagtail/
.. image:: https://img.shields.io/pypi/v/wagtail.svg
    :target: https://pypi.python.org/pypi/wagtail/
.. image:: http://codecov.io/github/wagtail/wagtail/coverage.svg?branch=master
    :target: http://codecov.io/github/wagtail/wagtail?branch=master


Wagtail CMS
===========

Wagtail is a content management system built on Django. It's focused on user experience,
and offers precise control for designers and developers.

.. image:: http://i.imgur.com/hSVerKq.jpg
   :width: 728 px

Features
~~~~~~~~

* A fast, attractive interface for authors and editors
* Complete control over design with standard Django templates
* Configure content types through standard Django models
* Fast out of the box. Cache-friendly if you need it
* Tightly integrated search
* Strong document and image management
* Wide support for embedded content
* Straightforward integration with existing Django apps
* Simple, configurable permissions
* Workflow support
* An extensible `form builder <http://docs.wagtail.io/en/latest/reference/contrib/forms/index.html>`_
* Multi-site and multi-language support
* Excellent `test coverage <http://codecov.io/github/wagtail/wagtail?branch=master>`_

Find out more at `wagtail.io <http://wagtail.io/>`_.

Getting started
~~~~~~~~~~~~~~~

.. code-block:: sh

    pip install wagtail
    wagtail start mysite
    cd mysite
    python manage.py migrate
    python manage.py createsuperuser
    python manage.py runserver

then sign in at http://127.0.0.1:8000/admin/

For detailed installation and setup docs, see `docs.wagtail.io <http://docs.wagtail.io/>`_.

Who's using it?
~~~~~~~~~~~~~~~
`madewithwagtail.org <http://madewithwagtail.org>`_ lists some of the public Wagtail sites we know about; please `add your own <http://madewithwagtail.org/submit/>`_.

Documentation
~~~~~~~~~~~~~
`docs.wagtail.io <http://docs.wagtail.io/>`_ is the full reference for Wagtail, and includes guides for developers, designers and editors, alongside release notes and our roadmap.

Community Support
~~~~~~~~~~~~~~~~~
There is an active community of Wagtail users and developers responding to questions on `Stack Overflow <http://stackoverflow.com/questions/tagged/wagtail>`_. When posting questions, please read Stack Overflow's advice on `how to ask questions <http://stackoverflow.com/help/how-to-ask>`_ and remember to tag your question with "wagtail".

For topics and discussions that do not fit Stack Overflow's question-and-answer format, there is also a `Wagtail Support mailing list <https://groups.google.com/forum/#!forum/wagtail>`_ and a `Slack workspace <https://github.com/wagtail/wagtail/wiki/Slack>`_.

Commercial Support
~~~~~~~~~~~~~~~~~~
Wagtail is sponsored by `Torchbox <https://torchbox.com/>`_. If you need help implementing or hosting Wagtail, please contact us: hello@torchbox.com.

Thanks
~~~~~~
We thank `BrowserStack <https://www.browserstack.com/>`_, who provide the project with free access to their live web-based browser testing tool, and automated Selenium cloud testing.

.. image:: https://cdn.rawgit.com/wagtail/wagtail/master/.github/browserstack-logo.svg
    :target: https://www.browserstack.com/
    :width: 219 px

Compatibility
~~~~~~~~~~~~~
Wagtail supports Django 1.11.x and 2.0 on Python 3.4, 3.5 and 3.6. Supported database backends are PostgreSQL, MySQL and SQLite.

Contributing
~~~~~~~~~~~~
If you're a Python or Django developer, fork the repo and get stuck in! We run a separate group for developers of Wagtail itself at https://groups.google.com/forum/#!forum/wagtail-developers (please note that this is not for support requests).

You might like to start by reviewing the `contributing guidelines <http://docs.wagtail.io/en/latest/contributing/index.html>`_ and checking issues with the `good first issue <https://github.com/wagtail/wagtail/labels/good%20first%20issue>`_ label.

We also welcome translations for Wagtail's interface. Translation work should be submitted through `Transifex <https://www.transifex.com/projects/p/wagtail/>`_.