[TYPO3-english] REALURL - No hashcode/parameters passed -- Exclude Page from url
Tobias Dörner
hermes1 at web.de
Thu Mar 24 17:25:30 CET 2011
Hi Dimtry,
/* remember asking Jan to
Reformat*/
I remember I have read about that. It was a few years ago, wasnt it?
Regards
-----Ursprüngliche Nachricht-----
Von: typo3-english-bounces at lists.typo3.org
[mailto:typo3-english-bounces at lists.typo3.org] Im Auftrag von Dmitry Dulepov
Gesendet: Donnerstag, 24. März 2011 16:43
An: typo3-english at lists.typo3.org
Betreff: Re: [TYPO3-english] REALURL - No hashcode/parameters passed --
Exclude Page from url
Hi!
Tobias Dörner wrote:
> Hi,
> /* SQL injection in it...*/
> fixed?
Yes. But due to messy code we were not able to audit the rest of the
extension for other issues. It is too difficult to understand what it does,
even for experienced TYPO3/PHP developers. I remember asking Jan to
reformat the code according to TYPO3 CGL and write comments but he said he
has no time.
May be the code changed since those time, I do not know. Never used CoolURI
again. I mostly rely on RealURL autoconfiguration. Usually it works out of
the box.
--
Dmitry Dulepov
TYPO3 core&security team member
E-mail: dmitry.dulepov at typo3.org
Web: http://dmitry-dulepov.com/
_______________________________________________
TYPO3-english mailing list
TYPO3-english at lists.typo3.org
http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-english
More information about the TYPO3-english
mailing list