[Typo3-dev] Install Tool Suggestion: Disallowed Extensions

4Dfx peter.russ at 4dfx.de
Thu Sep 11 23:44:27 CEST 2003


Jochen Weiland schrieb:
> Peter,
> 
> I am not sure whether I understand your posting correctly:
> 
> In the Typo3 configuration I already have disallowed the admins to install extensions globally, so they can install only to their own local extension directory. But there they could still install harmful extensions that may jeopardize the server. 
> 
> Jochen
[...]

You're running Typo3 on a Linux System with sym links for the global 
pathes and virtual hosts for your customer and their own DBs? Then you 
can handle everthing with the user/group permissions.
You should think about resticting system calls from PHP.
Additionally you can configure Apache in that way that the maximum usage 
of CPU and memory per session/child is limited.
If your customer has no right to change/install global extensions and 
your systems is set up proberly you're fine.

Did I forgot something ?

Regs. Peter.

www.4dfx.de









More information about the TYPO3-dev mailing list