Getting to grips with a Sitecore 7.2 JQuery Modal Dialog Box Issue

Posted 13 January 2015 12:00 AM by Alan Yip, Senior Sitecore Consultant @ ClearPeople

So you’ve installed a vanilla install of Sitecore 7.2 and you are about to give it a test run to make sure that basic features like content creation and publishing works. But you stumble across a weird issue when you try to publish an item and no popup is displayed! In fact, if you try any function where the new modal dialog Sitecore popup is used, you will notice that none of this actually works now…

The Issue

In Sitecore 7.2, XAML is still widely used throughout the admin pages and in some cases, the new JQuery modal dialog is used, for instance the publish item popup. An example of this popup is shown below:

sitecore popup 

 
You will notice that the XAML windows are not affected by this issue, but only the new JQuery ones are. This is not easily identifiable at first but I will explain how you will find out what causes this.

The Cause

If you are in Chrome (And no, this is not related to the Chrome Modal Dialog issue) you will want to press F12 to bring up the developer toolbar. You will notice the following error messages as shown below:

error message 


You will notice some JavaScript errors being fired when you refresh the admin page. Highlighted is the term “rejected-by-urlscan”. This is the cause and if you are getting this error, then you are in luck because there is a solution for this.

The solution

In IIS and under ISAPI Filters for your website, you will probably have URLScan 3.1 installed on your server for penetration test fixes. This is a module that you install in IIS to lock down certain HTTP requests. 

You can remove this from your list of ISAPI Filters and your popups will function again with no problem and this is a solution from some Googling.

But you may not be in the position to do this because it may fail your penetration tests. So what can we do instead?

The problem is that the default installation has the following configuration set to false:

AllowDotInPath=0

This basically says that URL paths cannot have more than 1 dot in its URL and if it does, then it will return a 404 for that file. The problem we have with websites nowadays (including Sitecore) is that JQuery files for instance have dots everywhere! (well, not everywhere) so these always return a 404, thus stopping most of your JQuery features from functioning.

So to get around not removing URLScan from your website, you can set this property to 1 and reset IIS and you’re good to go!

Please note that you will need to work with your penetration company to make sure that by removing this you mitigate other areas.

Share:

Add your comment

 
 

 

Archive

Tagcloud

Digital Transformation employee engagement staff satisfaction productivity Microsoft Teams Office 365 Yammer cms content management system agile GDPR Microsoft Graph collaboration Microsoft sharepoint 2016 upgrade migration SharePoint Online 2016 Tech Trends Digital Disruption Context marketing marketing SharePoint 2010 SharePoint 2013 TFS Git security kentico Analytics intranet jquery QA Quality Assurance testing digital workspace content management websites Sitecore sitecore marketplace sitecore module cloud Microsoft Cloud Storage digital strategy technical consulting sitecore modules Experience database Sitecore 7 Sitecore 8 support account management customer experience Data Storage windows azure cms integration front end front end development prototype Cloud Storage StorSimple Front-end Development Layout SharePoint 2013 colour palette UI design website design log viewer sitecore cms website Azure big data business-critical sharepoint accessibility android apple chrome clear people clearpeople debug emulator ios mobile testing opera resize adobe desktop flash ie10 internet explorer 10 metro windows 8 bcsp SharePoint Advanced System Reporter reporting framework ControlMode form control master page placeholder publishing console SharePoint 2007 SharePoint error search search results search values software testing testing scenario audit content information architecture retention schedules PowerShell QuickLaunch scripts SharePoint server 2010 business solutions metalogix replication replicator storagepoint stena technet UK Technet picture library slideshow web part RTM released to manufacturing caml caml query MOSS 2007 query infopath