[TYPO3-t3board] Suggestion for a meeting at T3BOARD

Nicolas de Haen typo3 at ndh-websolutions.de
Fri Feb 15 10:59:48 CET 2013


Hi all,

I want to suggest a meeting at the T3BOARD to discuss the following topic:

Since I just have 2 projects where I have to implement access control in 
extbase I wonder, if it might make sense to migrate the authorization 
part of the FLOW security framework to extbase (instead of implementing 
some "individual" solution).

Since we don't have AOP we would have to "hardcode" some "advice" calls 
in certain "join points" and there are certainly some more limitations 
(no context etc.) but if we could configure policies for controller 
actions and object/property access that would be a huge step towards 
more security.

It would be nice also to have something like the 
PersistenceQueryRewritingAspect in the Persistence, to control access on 
a low level. (for example "enable fields"...)

So I'm eager to hear what you think about this:

- has this been discussed already?
- are there already plans to implement something like that?
- do you think it would make sense at all?

If you are also interested in a meeting please reply to this mail.


regards,
Nico


-- 
Nico de Haen
ndh websolutions

Webprogrammierung, OpenSource, Typo3



http://www.ndh-websolutions.de


More information about the T3board mailing list