[TYPO3-english] tcemain and fe extensions

Dmitry Dulepov dmitry.dulepov+t3ml at gmail.com
Mon Feb 22 17:04:05 CET 2010


Hi!

On 2010-02-22 17:37:59 +0200, Rik Willems said:
> Thank you for the clear instructions.
> Is there a security issue involved in using tcemain in fe?

No, it is not security. Many hooks will expect a fully loaded BE 
environment. As a result data can become corrupted in places where you 
do not expect it.

> I found that hooks do work properly because they are called when 
> executing tcemain.

Some do, many will not. If you want to risk, you can do it. I would 
never do it because it is not what should be done. TCEmain is not for 
FE. I have no way to stop you from doing this but if you want a good 
advice: do not use TCEmain in FE. That's all I can say.

-- 
Dmitry Dulepov
TYPO3 expert / TYPO3 security team member 
Read more @ http://dmitry-dulepov.com/



More information about the TYPO3-english mailing list