[TYPO3-core] RFC: #9758: Write Configuration to extTables.php

Martin Kutschker masi-no at spam-typo3.org
Tue Nov 11 10:05:16 CET 2008


Franz Holzinger schrieb:
> Martin Kutschker a écrit :
>> Dmitry Dulepov schrieb:
>>> There are cases when you have several admin users but not every
>>> admin user can use Install tool. You know, install tool is protected
>>> by a special password even when you are logged in as admin. There
>>> are cases when only a certain admin should be able to change
>>> settings system wide.
>>
>> Why not ask the user for the install tool password here as well?
> 
> No, it would be bad to force an admin to enter passwords so often.
> You better make the feature superadmin for an admin who is allowed to do
> everything.
> 
>> This extension should also use an extra password. As should IMHO
>> phpMyAdmin.
> The same here.

You must enter it only once for the session. Superadmin or not I really
think that these extension have no extra password protection is a flaw.

Masi


More information about the TYPO3-team-core mailing list