[TYPO3-english] MnoGoSearch and access restrictions

Dmitry Dulepov dmitry at typo3.org
Wed Mar 18 10:37:47 CET 2009


Hi!

Feodor Rykhtik wrote:
> There is an another model : assigh to mnogoSearch user multitude of FE
> - groups and to receive one version, the most complete.

Ok, let's suppose the page contains ssh connection details that are visible to some users only. Now if I search for "ssh", I will get all password in the preview that mnogosearch generates. This is a security hole.

> Of course, possibility to make different versions for each FE-user -
> some problematic, need to add some functionality to mnogoSearch
> indexer/search engine. For this - need to contact authors of the
> search engine and to ask the possibility of records/versionning with
> dB-separation by unique key of "watcher".

Yes, I thought about it. But nothing happens for free. Even when they are contacted, they do not reply unless they see a potential contract or something.

I think about modifying their C code myself. I will need to add click recording there anyway...

-- 
Dmitry Dulepov
TYPO3 core team
http://dmitry-dulepov.com/article/typo3-extension-update-google-sitemap.html


More information about the TYPO3-english mailing list