[TYPO3-dev] Meta tag "noindex, nofollow" on development domain
Thomas "Thasmo" Deinhamer
thasmo at gmail.com
Thu Aug 19 00:17:24 CEST 2010
Christopher Torgalson wrote:
> I can't offer an opinion about how severe it is, but this method is
> risky to some extent (it used to be possible to set config.baseURL to
> the value of HTTP_HOST automatically, but this capability was removed
> due to the risk).
Hello Christopher!
I'm aware of this security problem and that the possibility has been
removed. Nevertheless I'm not setting the config.baseUrl using
conditions. Actually I try to avoid setting the baseUrl, but try to use
the "config.absRefPrefix = /" setting wherever possible. (Rest is done
using domain records etc.)
I just needed the conditions for disabling search engine indexing and
google tracking in first place. Of course I'm interested in any security
issue regarding the usage of a condition on the HTTP_HOST!
Thanks a lot,
Thomas
More information about the TYPO3-dev
mailing list