[TYPO3] Enable template editing for non admins?
Patrick Gaumond
patrick at typo3quebec.org
Tue Nov 14 20:44:55 CET 2006
Staffan Ericsson wrote:
>> TS template is limited to admins by design.
>
> That was sad news for me. Then I will have to do more work or reduce the
> security of the site....
If templates where available to non-admin your site would also be less
secure since your non-admin template editor could add some PHP that get
passwords or other things...
So the design decision is still valid: don't give rights to templates
for non-admin users because it would give a false impression of security.
The long-term solution would be to add some pre-process to templates
that parse them to see if some PHP is present. Just an idea. I'm not
that aware of the internals...
Patrick
More information about the TYPO3-english
mailing list