Dmitry,
On Thu, Apr 27, 2017 at 9:53 PM, Dmitry Sotnikov <dmi...@wso2.com> wrote:

> In API Cloud's developer portal, we allow custom CSS code, fonts as SVG,
> TTF, EOT, WOFF , WOFF2 and OTF files, and images as JPG, PNG, and GIF files.
>

In our scenario also, we keep a server level config similar to [1] to white
list allowed file types, which can modify using custom themes. So we can
allow any of the listed files.

[1]
"customStoreThemeConfig" : {
         "whitelist" : ["css", "svg"]
}

>
> Sometimes customers do want to go beyond that: for example, remove certain
> sections of the site - but we do not have such a capability at the moment.
>

We decided not to whitelist jag, hbs, js files because, it can make
security loopholes.  @Some ui experts should be able to give feedback on it.

Regards,
Dinusha

>
> On Thu, Apr 27, 2017 at 3:23 AM, Ashen Weerathunga <as...@wso2.com> wrote:
>
>> Hi all,
>>
>> We are in the process of implementing custom theming support for
>> identity cloud user portal. This will allow customers to do the following
>> tasks based on their preference.
>>
>>    - Change the color theme of the user portal.
>>    - Change company logo on the header.
>>
>> Users will be provided a UI to upload and delete themes from the admin
>> portal and they need to upload the customized theme as a zip file. Then the
>> uploaded theme will be deployed tenant wise in the user portal. The
>> wireframe design for the UI can be found at [1][2].
>>
>> [1]https://github.com/wso2-dev-ux/product-cloud/blob/master/
>> Wireframes/identity_cloud/1.2.0/017%20Identity%20Cloud%20-%2
>> 0Theme%20-%20Upload%20.png
>> [2]https://github.com/wso2-dev-ux/product-cloud/blob/master/
>> Wireframes/identity_cloud/1.2.0/018%20Identity%20Cloud%20-%2
>> 0Theme%20-%20after%20adding%20a%20custom%20theme.png
>>
>> Appreciate any suggestions regarding this.
>>
>> Thanks,
>> Ashen
>>
>> --
>> *Ashen Weerathunga*
>> Software Engineer
>> WSO2 Inc.: http://wso2.com
>> lean.enterprise.middleware
>>
>> Email: as...@wso2.com
>> Mobile: +94716042995 <94716042995>
>> LinkedIn: *http://lk.linkedin.com/in/ashenweerathunga
>> <http://lk.linkedin.com/in/ashenweerathunga>*
>> <http://wso2.com/signature>
>>
>
>
>
> --
> Dmitry Sotnikov
> VP of Cloud; WSO2, Inc.;  http://wso2.com/
> email: dmi...@wso2.com; cell: +1.949.303.9653 <+1%20949-303-9653>
> ; Skype: DSotnikov
> Lean . Enterprise . Middleware
>
> <http://wso2.com/signature>
>



-- 
Dinusha Dilrukshi
Technical Lead
WSO2 Inc.: http://wso2.com/
Mobile: +94764069991 <076%20406%209991>
Blog: http://dinushasblog.blogspot.com/
_______________________________________________
Architecture mailing list
Architecture@wso2.org
https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture

Reply via email to