[TYPO3-english] MnoGoSearch and access restrictions

Feodor Rykhtik feodor.rykhtik at gmail.com
Wed Mar 18 12:22:25 CET 2009


Dmitry Dulepov wrote :
> Now if I search for "ssh", I will get all password in the preview that mnogosearch generates.
> This is a security hole.

Yep, it coud be. But imagine You have different fe-groups in Your
TYPO3 installation : feusers, fevip, fessh. It's possible to propose
to mnogosearch only "feusers" + "fevip" contents (could be done
through Page TSConfig, for example). And not to show the content
reserved for "fessh" group, as TopSecret information.

Of course, it's some special, but it could be a PHP solution.

> I think about modifying their C code myself. I will need to add click recording there anyway...
Thought about this. For the instance - we had implemented different
PHP solutions.
Just a question if it's possible to upload the TYPO3 hooks to the SVN
of "mnogoSearch".
Or it should be done as external pathches before the compliation ?

Regards,
Feo.


More information about the TYPO3-english mailing list