[TYPO3-core] RFC #15504: Description of TYPO3_CONF settings should allow HTML markup for readability

Ernesto Baschny [cron IT] ernst at cron-it.de
Thu Aug 19 17:51:57 CEST 2010


David Bruchmann schrieb am 19.08.2010 17:42:
> ----- Ursprüngliche Nachricht -----
> Von:        Steffen Kamper <info at sk-typo3.de>
> Gesendet:   Donnerstag, 19. August 2010 17:18:33
> An:         typo3-team-core at lists.typo3.org
> CC:
> Betreff:    Re: [TYPO3-core] RFC #15504: Description of TYPO3_CONF
> settings should allow HTML markup for readability
>> Hi Ernesto,
>>
>> +1 by reading and testing.
>> I changed <p> to <.*?> to allow all kind of tags there (v2).
>>
>> The complete parsing of config_default is really too magic and cryptic,
>> so i like your little enhancement, as it'S really important to show the
>> meaning of the parameters very clear. Therefore html is needed to
>> structure the description.
>>
>> vg Steffen
>>
> 
> 
> Hi,
> 
> I didn't test it and you can correct me if I'm wrong:
> 
> Is it possible to insert iframes or script-tags?
> 
> If yes: is it a security-issue perhaps?

Everything is possible. It is a security issue if some patch enters that
core that includes them. The whole config_default.php is not written by
anyone except the core developers. You'll have to trust us.  ;)


Cheers,
Ernesto


More information about the TYPO3-team-core mailing list