[TYPO3-german] jumpurl Fehler nach Update auf 4.7.9

Gregor Hermens gregor at a-mazing.de
Wed Mar 6 16:28:11 CET 2013


Hallo Christoph,

Christoph Walser wrote:

> ich habe nach dem heutigen Security Advisory (
> http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-
sa-2013-001/
> ) von   4.7.8 auf 4.7.9 upgegraded und jetzt funktioniert ein Menupunkt
> nicht mehr auf welchen ein Link hinterlegt ist ("Link to external URL").
> Anstatt auf die Externe Seite weiterzuleiten wird nun folgender Fehler
> angezeigt:

siehe das offizielle Security-Bulletin:

http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-
sa-2013-001/

Zitat:
-----
Important Notes: To fix this vulnerability, we had to break existing 
behaviour of TYPO3 sites that use the access tracking mechanism (jumpurl 
feature) to transform links to external sites. The link generation has been 
changed to include a hash that is checked before redirecting to an external 
URL. This means that old links that have been distributed (e.g. by a 
newsletter) will not work any more. If you are using the jumpurl feature you 
need to do the following:

    Clear the TYPO3 caches to prevent old links without required validation 
hash will be delivered

If it is important that already distributed links  (e.g. by directmail 
newsletter module) are still working, you have to additionally:

    Install the provided extension (t3x, zip) which covers the following 
cases:
        URLs which are present in pages or content elements are allowed to 
be redirected to, even if the validation hash is missing or wrong.
        URLs which are present in newletters sent using the third party 
module "directmail" are allowed to be redirected to, even if the validation 
hash is missing or wrong.

If the above usecases do not cover your needs, you need to:

    Adapt the provided extension or create your own extension with a 
redirect handler that fits your needs.

If you have further questions regarding this issue, feel free to ask on a 
public mailing list or in our forum to get the needed support.
-----

hth
Gregor
-- 
http://www.a-mazing.de/   |   Certified TYPO3 Integrator



More information about the TYPO3-german mailing list