[Typo3-dev] Security: limit extension available to install

Karsten Dambekalns k.dambekalns at fishfarm.de
Thu Jan 13 16:51:39 CET 2005


Hello Sebastian!

Sebastian Kurfuerst wrote:

[Pfui - TOFU]

> Karsten Dambekalns wrote:
>> How would you set up such a whitelist, so that the admin acnnot
>> circumvent it? And that is needed, since only an admin is allowed to
>> install extensions anyway.
>> 
> If we make the white list configurable in the install tool, the TYPO3 BE
> Admin has no access to it if he doesn't know the install tool password.

Ah. Ok, that works - didn't think of it, as I always have access to the
install tool on the sites I take care of.

So basically everything that restricts an admin has to be done in the
install tool, to which said admin has no access. Klar wie Kloßbrühe. :)

Karsten




More information about the TYPO3-dev mailing list