[TYPO3-core] RFC #11586: Problem with fix of the SQL injection bug

Xavier Perseguers typo3 at perseguers.ch
Thu Oct 22 19:36:05 CEST 2009


Hi,

This is a SVN follow-up patch request.

I cannot find this RFC in this mailing list and associated bug in bugtracker has its access being denied.

As found by Simon Browning in dev list with thread "4.3 beta 2 - problem with Front end Editing". The change introduced a bug by introducing new class member TSFE_EDIT defined as protected whereas a 
consequent bunch of code in Core (including both old and new feedit) used this variable as public.

The changeset created this member which was previously implicitly defined.

Problem: field was made protected whereas it should be made public if one does not want to go through all Core to use a getter instead.

Might apply to other branches as well (don't know, cannot access bugtracker).

Regards

-- 
Xavier Perseguers
http://xavier.perseguers.ch/en

One contribution a day keeps the fork away
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: followup_11586.diff
URL: <http://lists.typo3.org/pipermail/typo3-team-core/attachments/20091022/6f67ab3a/attachment.asc>


More information about the TYPO3-team-core mailing list