[TYPO3-core] RFC #12436: Integrate checks concerning Suhosin/Hardened PHP in Install Tool

Martin Kutschker masi-no at spam-typo3.org
Sat Nov 7 19:06:02 CET 2009


Marcus Krause schrieb:

>> Solution:
>> A part in the install tool should check whether Suhosin is active and
>> whether the PHP configuration for that should be changed - e.g.:
>> * suhosin.request.max_vars - default is 200, should be 500 or more
>> * suhosin.post.max_vars - default is 200, should be 400 or more
> 
> Are there any tests/bug reports that indicate the necessity to raise
> those limits?

The main problem with Suhosin is that it simply drops the fields. No error, no warning, no
exception, no nothing. Me and colleagues have spent hours debugging when we ran into it Suhosin's
limits.

I had the idea to use a checker field as the very last field to protect against silent field drops
by Suhosin.

Masi


More information about the TYPO3-team-core mailing list