[TYPO3-dev] Meta tag "noindex, nofollow" on development domain

Thomas "Thasmo" Deinhamer thasmo at gmail.com
Thu Aug 19 00:17:24 CEST 2010


Christopher Torgalson wrote:
> I can't offer an opinion about how severe it is, but this method is
> risky to some extent (it used to be possible to set config.baseURL to
> the value of HTTP_HOST automatically, but this capability was removed
> due to the risk).

Hello Christopher!

I'm aware of this security problem and that the possibility has been 
removed. Nevertheless I'm not setting the config.baseUrl using 
conditions. Actually I try to avoid setting the baseUrl, but try to use 
the "config.absRefPrefix = /" setting wherever possible. (Rest is done 
using domain records etc.)

I just needed the conditions for disabling search engine indexing and 
google tracking in first place. Of course I'm interested in any security 
issue regarding the usage of a condition on the HTTP_HOST!

Thanks a lot,
Thomas




More information about the TYPO3-dev mailing list