[TYPO3-dev] Meta tag "noindex, nofollow" on development domain
    Thomas "Thasmo" Deinhamer 
    thasmo at gmail.com
       
    Thu Aug 19 00:17:24 CEST 2010
    
    
  
Christopher Torgalson wrote:
> I can't offer an opinion about how severe it is, but this method is
> risky to some extent (it used to be possible to set config.baseURL to
> the value of HTTP_HOST automatically, but this capability was removed
> due to the risk).
Hello Christopher!
I'm aware of this security problem and that the possibility has been 
removed. Nevertheless I'm not setting the config.baseUrl using 
conditions. Actually I try to avoid setting the baseUrl, but try to use 
the "config.absRefPrefix = /" setting wherever possible. (Rest is done 
using domain records etc.)
I just needed the conditions for disabling search engine indexing and 
google tracking in first place. Of course I'm interested in any security 
issue regarding the usage of a condition on the HTTP_HOST!
Thanks a lot,
Thomas
    
    
More information about the TYPO3-dev
mailing list