[TYPO3] Enable template editing for non admins?

Patrick Gaumond patrick at typo3quebec.org
Tue Nov 14 20:44:55 CET 2006


Staffan Ericsson wrote:

>> TS template is limited to admins by design.
> 
> That was sad news for me. Then I will have to do more work or reduce the
> security of the site....

If templates where available to non-admin your site would also be less 
secure since your non-admin template editor could add some PHP that get 
passwords or other things...

So the design decision is still valid: don't give rights to templates 
for non-admin users because it would give a false impression of security.

The long-term solution would be to add some pre-process to templates 
that parse them to see if some PHP is present. Just an idea. I'm not 
that aware of the internals...

Patrick



More information about the TYPO3-english mailing list