Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-38988

change fontset 'icons' to html entities to improve security compliance

    • 0
    • 1
    • We collect Confluence feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      NOTE: This suggestion is for Confluence Server. Using Confluence Cloud? See the corresponding suggestion.

      It seems that the icons in Confluence are currently rendered using fontset. This can be an issue for organization especially banks that have strict security constraint (fontset cannot be downloaded) as a result this will not render on customer instance.

      I would recommend that we change the current method of icons being rendered using fontset being changed to HTML entities instead.

      There is also a security issue which have been reported by Microsoft recently the link can be found below :
      https://support.microsoft.com/en-gb/kb/3079904

      You can see an example of a customer instance not rendering the fontset icons as per the screenshot attached below :

        1. CONFKBpage.jpg
          CONFKBpage.jpg
          61 kB
        2. fontset not rendering.jpg
          fontset not rendering.jpg
          15 kB

          Form Name

            [CONFSERVER-38988] change fontset 'icons' to html entities to improve security compliance

            And continues ... having "upgraded" (the term becoming more and more of a joke here) from 5.4 to 5.9 we find that links on pages to PDF page attachments are now rendered using some Confluence built-in PDF viewer, rather than triggering a request to open in the browser's usual PDF viewer (typically Acrobat Reader).

            This is all well and good for PDF's with basic fonts, but if the PDF has any interesting fonts (eg: complex maths formulae) they are invisible.

            Peter Binney added a comment - And continues ... having "upgraded" (the term becoming more and more of a joke here) from 5.4 to 5.9 we find that links on pages to PDF page attachments are now rendered using some Confluence built-in PDF viewer, rather than triggering a request to open in the browser's usual PDF viewer (typically Acrobat Reader). This is all well and good for PDF's with basic fonts, but if the PDF has any interesting fonts (eg: complex maths formulae) they are invisible.

            The destruction of the Confluence UI continues ;-((

            5.9 has removed the "Attachments" paperclip to the right of the breadcrumb.
            I has also introduced a "Restrictions" padlock that is invisible.

            Peter Binney added a comment - The destruction of the Confluence UI continues ;-(( 5.9 has removed the "Attachments" paperclip to the right of the breadcrumb. I has also introduced a "Restrictions" padlock that is invisible.

            How can I escalate this to get someone with common-sense and authority to realise what a mess has been made of your products?

            Please see the attached screenshot (CONFKBpage.jpg) from of one of your own Internet websites, showing just how unusable it is (eg: no Tools menu) for security conscious organisations.

            Peter Binney added a comment - How can I escalate this to get someone with common-sense and authority to realise what a mess has been made of your products? Please see the attached screenshot (CONFKBpage.jpg) from of one of your own Internet websites, showing just how unusable it is (eg: no Tools menu) for security conscious organisations.

            In addition to the screenshots above, a particularly invidious absence is the ever-so cryptic "Tools" option when viewing a page.

            In 5.4 this shows as the word "Tools" with a dropdown arrow and cogwheel icon.
            In 5.8 is is just three dots (which even if you see it is far from intuitive; it doesn't even have a tooltip!).
            But if you don't have the fonts downloaded it is missing completely and the user has no access to, inter alia:

            • Page History
            • Restrictions
            • Favourite
            • Copy
            • Move
            • Delete

            Clearly Alassian's UI-Fuehrer thinks it more important to have smart-phone look and feel rather than a usable product.

            Peter Binney added a comment - In addition to the screenshots above, a particularly invidious absence is the ever-so cryptic "Tools" option when viewing a page. In 5.4 this shows as the word "Tools" with a dropdown arrow and cogwheel icon. In 5.8 is is just three dots (which even if you see it is far from intuitive; it doesn't even have a tooltip!). But if you don't have the fonts downloaded it is missing completely and the user has no access to, inter alia: Page History Restrictions Favourite Copy Move Delete Clearly Alassian's UI-Fuehrer thinks it more important to have smart-phone look and feel rather than a usable product.

              Unassigned Unassigned
              dooi Der Lun
              Votes:
              1 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: