[TYPO3-ttnews] tt_news bugfixing day

Rupert Germann rupi at gmx.li
Thu Nov 26 15:31:59 CET 2009


Marcus 'biesior' Biesioroff schrieb:
> W dniu 2009-11-26 00:42, Rupert Germann pisze:
>> I have to admit that I consider it as a kind of a security issue if
>> non-admin users have access to typoscript. But since some other widely
>> used extensions offer this possibility, too, I added it also to tt_news.
> 
> This thing should be considered every time by the implementation's 
> developer, as it can be still disabled for BEusers.

unfortunately TYPO3 provides no way to hide single flexform fields for 
certain users. the only way the hide a field are conditions. In this 
case the condition "hide_for_nonadmins" does what I want and so I use it 
for the "typoscript" field.

I committed the following changes to tt_news trunk rev 27029.

changes:
- removed tab "Typoscript" from flexform and moved the new "typoscript" 
field to the "other settings" tab
- added a condtion to the flexform field "typoscript" which hides this 
field from non-admin users


greets
rupert


More information about the TYPO3-project-tt-news mailing list