[TYPO3-mvc] Request hash (HMAC) checking failed

Helmut Hummel helmut.hummel at typo3.org
Wed Apr 25 22:18:07 CEST 2012


Hi,

On 23.04.12 20:58, Valentin Zickner wrote:

> you can use in the @dontverifyrequesthash annotation. In this case
> extbase ignore incorrect request hashes.

I would recommend reading the extbase security cookbook[1] section about 
"mass assignment" when doing that.

Also make sure you have no create or delete actions left that from 
extensionbuilder generated code!


Kind regards,
Helmut

[1]http://forge.typo3.org/projects/typo3v4-mvc/wiki/Extbase__FLOW3_Security_Cookbook

-- 
Helmut Hummel
TYPO3 Security Team Leader, TYPO3 v4 Core Team Member

TYPO3 .... inspiring people to share!
Get involved: typo3.org


More information about the TYPO3-project-typo3v4mvc mailing list