[TYPO3-t3board] Suggestion for a meeting at T3BOARD
Nicolas de Haen
typo3 at ndh-websolutions.de
Fri Feb 15 10:59:48 CET 2013
Hi all,
I want to suggest a meeting at the T3BOARD to discuss the following topic:
Since I just have 2 projects where I have to implement access control in
extbase I wonder, if it might make sense to migrate the authorization
part of the FLOW security framework to extbase (instead of implementing
some "individual" solution).
Since we don't have AOP we would have to "hardcode" some "advice" calls
in certain "join points" and there are certainly some more limitations
(no context etc.) but if we could configure policies for controller
actions and object/property access that would be a huge step towards
more security.
It would be nice also to have something like the
PersistenceQueryRewritingAspect in the Persistence, to control access on
a low level. (for example "enable fields"...)
So I'm eager to hear what you think about this:
- has this been discussed already?
- are there already plans to implement something like that?
- do you think it would make sense at all?
If you are also interested in a meeting please reply to this mail.
regards,
Nico
--
Nico de Haen
ndh websolutions
Webprogrammierung, OpenSource, Typo3
http://www.ndh-websolutions.de
More information about the T3board
mailing list