# Smarty: not allowed by security setting (konkreter Fall)

**URL:** <https://forum.shopware.com/t/smarty-not-allowed-by-security-setting-konkreter-fall/56935>\
**Category:** Programmierung\
**Created:** [7. Dezember 2018 um 08:48 UTC](https://forum.shopware.com/t/smarty-not-allowed-by-security-setting-konkreter-fall/56935 "2018-12-07T08:48:06Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![webarbeit](https://avatars.discourse-cdn.com/v4/letter/w/b487fb/32.png) [@webarbeit](https://forum.shopware.com/u/webarbeit)\
**Post date:** [7. Dezember 2018 um 08:48 UTC](https://forum.shopware.com/t/smarty-not-allowed-by-security-setting-konkreter-fall/56935/1 "2018-12-07T08:48:06Z")

</div>

Hallo zusammen,

ich bekomme aktuell bei einem Plugin noch folgenden Fehler (obwohl das Template-Verzeichnis ganz oben registriert wird):

```
directory '/var/www/xyz/engine/Shopware/Plugins/Community/Frontend/xyz/Views/frontend/listing/product-box/product-actions.tpl' not allowed by security setting
2018-12-07T09:21:00.908658+0100
core
{
    "uri": "/widgets/listing/listingCount/sSupplier/169/sCategory/3?p=2&productBoxLayout=basic&c=3&o=1&n=36&loadProducts=1",
    "method": "GET",
    "query": {
        "p": "2",
        "productBoxLayout": "basic",
        "c": "3",
        "o": "1",
        "n": "36",
        "loadProducts": "1",
        "module": "widgets",
        "controller": "listing",
        "action": "listingCount",
        "sSupplier": "169",
        "sCategory": "3",
        "sPage": "2",
        "sPerPage": "36",
        "sSort": "1"
    },
    "post": []
}
No session data available
1
xyz.de

```

Hier die entscheidenden Zeilen aus dem Plugin:

```
    private function subscribeEvents()
    {
        $this->subscribeEvent(
            'Enlight_Controller_Action_PostDispatchSecure_Frontend',
            'onPostDispatch'
        );
		
		$this->subscribeEvent(
			'Enlight_Controller_Action_PostDispatchSecure_Widgets',
			'onPostDispatch'
        );	
    }

    public function onPostDispatch(Enlight_Controller_ActionEventArgs $args)
    {
        $config = $this->Config();

        $view = $args->getSubject()->View();
		$view->addTemplateDir($this->Path() . 'Views');
		
		$view->assign('xyz', $config->xyz);        
    }

```

Hat jemand vielleicht ein Tipp dazu?

Viele Grüße und Dank vorab,  
Frank

---

<div class="post-metadata">

**Author:** ![Haraldio](https://avatars.discourse-cdn.com/v4/letter/h/e79b87/32.png) [@Haraldio](https://forum.shopware.com/u/Haraldio)\
**Post date:** [7. Dezember 2018 um 08:58 UTC](https://forum.shopware.com/t/smarty-not-allowed-by-security-setting-konkreter-fall/56935/2 "2018-12-07T08:58:41Z")

</div>

Hast [das hier](https://issues.shopware.com/issues/SW-19697)gesehen&nbsp;?

&nbsp;

---

<div class="post-metadata">

**Author:** ![webarbeit](https://avatars.discourse-cdn.com/v4/letter/w/b487fb/32.png) [@webarbeit](https://forum.shopware.com/u/webarbeit)\
**Post date:** [7. Dezember 2018 um 09:04 UTC](https://forum.shopware.com/t/smarty-not-allowed-by-security-setting-konkreter-fall/56935/3 "2018-12-07T09:04:49Z")

</div>

> [@Haraldio schrieb:](https://forum.shopware.com/profile/24921/Haraldio "Haraldio")
> 
> Hast [das hier](https://issues.shopware.com/issues/SW-19697?_ga=2.246690564.1011322618.1543827604-503160826.1531388062)gesehen&nbsp;?
> 
> &nbsp;

Nein, bisher nicht, vielen Dank. Aber ich werde, ehrlich gesagt, nicht schlau daraus. :-(&nbsp;

Bei mir steht dort folgendes drin:

```
{extends file="parent:frontend/listing/product-box/product-actions.tpl"}

```

&nbsp;

---

<div class="post-metadata">

**Author:** ![Haraldio](https://avatars.discourse-cdn.com/v4/letter/h/e79b87/32.png) [@Haraldio](https://forum.shopware.com/u/Haraldio)\
**Post date:** [7. Dezember 2018 um 09:12 UTC](https://forum.shopware.com/t/smarty-not-allowed-by-security-setting-konkreter-fall/56935/4 "2018-12-07T09:12:09Z")

</div>

Bin kein Profi - aber einer, der sich gern mal vertippt. Und soweit ich das verstehe, ist die Fehlermeldung mitunter irreführend, weil nicht die Berechtigung durch Smarty fehlt, sondern ein anderer Fehler auftritt - z.B. durch einen Tippfehler …

---

<div class="post-metadata">

**Author:** ![hhmarco73](https://avatars.discourse-cdn.com/v4/letter/h/ed8c4c/32.png) [@hhmarco73](https://forum.shopware.com/u/hhmarco73)\
**Post date:** [8. Dezember 2018 um 16:24 UTC](https://forum.shopware.com/t/smarty-not-allowed-by-security-setting-konkreter-fall/56935/5 "2018-12-08T16:24:37Z")

</div>

[https://secure.php.net/manual/en/function.dirname.php#refsect1-function.dirname-returnvalues](https://secure.php.net/manual/en/function.dirname.php#refsect1-function.dirname-returnvalues)

```
$view->addTemplateDir($this->Path() . '/Views');

```

&nbsp;

---

<div class="post-metadata">

**Author:** ![puhas](https://avatars.discourse-cdn.com/v4/letter/p/b38774/32.png) [@puhas](https://forum.shopware.com/u/puhas)\
**Post date:** [8. Dezember 2018 um 16:41 UTC](https://forum.shopware.com/t/smarty-not-allowed-by-security-setting-konkreter-fall/56935/6 "2018-12-08T16:41:21Z")

</div>

Das Template frühstmöglich registrieren heißt nicht, dass der Code dafür weit oben im Plugin steht. Du musst ein Event nutzen, das zeitlich früh gefeuert wird. PostDispatchSecure ist idR viel zu spät.

---

<div class="post-metadata">

**Author:** ![webarbeit](https://avatars.discourse-cdn.com/v4/letter/w/b487fb/32.png) [@webarbeit](https://forum.shopware.com/u/webarbeit)\
**Post date:** [8. Dezember 2018 um 18:43 UTC](https://forum.shopware.com/t/smarty-not-allowed-by-security-setting-konkreter-fall/56935/7 "2018-12-08T18:43:57Z")

</div>

> [@puhas schrieb:](https://forum.shopware.com/profile/2397/puhas "puhas")
> 
> Das Template frühstmöglich registrieren heißt nicht, dass der Code dafür weit oben im Plugin steht. Du musst ein Event nutzen, das zeitlich früh gefeuert wird. PostDispatchSecure ist idR viel zu spät.

Hast mir ggf. ein Beispiel dafür? Aus der Dokumentation werde ich leider nicht schlau.

Das Template in einem eigenen frühreren registrieren Event?

---

<div class="post-metadata">

**Author:** ![webarbeit](https://avatars.discourse-cdn.com/v4/letter/w/b487fb/32.png) [@webarbeit](https://forum.shopware.com/u/webarbeit)\
**Post date:** [8. Dezember 2018 um 18:53 UTC](https://forum.shopware.com/t/smarty-not-allowed-by-security-setting-konkreter-fall/56935/8 "2018-12-08T18:53:26Z")

</div>

> [@hhmarco73 schrieb:](https://forum.shopware.com/profile/24323/hhmarco73 "hhmarco73")
> 
> [https://secure.php.net/manual/en/function.dirname.php#refsect1-function.dirname-returnvalues](https://secure.php.net/manual/en/function.dirname.php#refsect1-function.dirname-returnvalues)
> 
> $view-\>addTemplateDir($this-\>Path() . ‚/Views‘);
> 
> &nbsp;

Was genau meinst Du damit?

Grüße Frank

---

<div class="post-metadata">

**Author:** ![puhas](https://avatars.discourse-cdn.com/v4/letter/p/b38774/32.png) [@puhas](https://forum.shopware.com/u/puhas)\
**Post date:** [8. Dezember 2018 um 18:59 UTC](https://forum.shopware.com/t/smarty-not-allowed-by-security-setting-konkreter-fall/56935/9 "2018-12-08T18:59:25Z")

</div>

> [@webarbeit schrieb:](https://forum.shopware.com/profile/24927/webarbeit "webarbeit")
> 
> > [@puhas schrieb:](https://forum.shopware.com/profile/2397/puhas "puhas")
> > 
> > Das Template frühstmöglich registrieren heißt nicht, dass der Code dafür weit oben im Plugin steht. Du musst ein Event nutzen, das zeitlich früh gefeuert wird. PostDispatchSecure ist idR viel zu spät.
> 
> Hast mir ggf. ein Beispiel dafür? Aus der Dokumentation werde ich leider nicht schlau.
> 
> Das Template in einem eigenen frühreren registrieren Event?

Dieser Beitrag erklärt es sehr gut: [https://forum.shopware.com/discussion/comment/209476/#Comment\_209476](https://forum.shopware.com/discussion/comment/209476/#Comment_209476)

---

<div class="post-metadata">

**Author:** ![hhmarco73](https://avatars.discourse-cdn.com/v4/letter/h/ed8c4c/32.png) [@hhmarco73](https://forum.shopware.com/u/hhmarco73)\
**Post date:** [9. Dezember 2018 um 18:44 UTC](https://forum.shopware.com/t/smarty-not-allowed-by-security-setting-konkreter-fall/56935/10 "2018-12-09T18:44:25Z")

</div>

> Was genau meinst Du damit?

Der Slash fehlt bei Dir&nbsp;
