[TYPO3-mvc] Tx_Extbase_MVC_Controller_Argument StoragePage

Sebastian Kurfürst sebastian at typo3.org
Tue Jul 6 09:40:12 CEST 2010


Hey,

I just had a quick phone call with Helmut Hummel from the Security Team
about this issue, as I was not sure if it had security implications.

We thought it through now, and as the EnableFields are respected
nevertheless, setting respectStoragePage to FALSE is no security issue.
Additionally, if any application really needs this behavior, this access
check should be done explicitely in the controller then.

So, a (late) +1 from my side as well!

Greets, and thanks all of you for your work,
Sebastian


More information about the TYPO3-project-typo3v4mvc mailing list