[TYPO3-core] RFC #15504: Description of TYPO3_CONF settings should allow HTML markup for readability
Ernesto Baschny [cron IT]
ernst at cron-it.de
Thu Aug 19 17:51:57 CEST 2010
David Bruchmann schrieb am 19.08.2010 17:42:
> ----- Ursprüngliche Nachricht -----
> Von: Steffen Kamper <info at sk-typo3.de>
> Gesendet: Donnerstag, 19. August 2010 17:18:33
> An: typo3-team-core at lists.typo3.org
> CC:
> Betreff: Re: [TYPO3-core] RFC #15504: Description of TYPO3_CONF
> settings should allow HTML markup for readability
>> Hi Ernesto,
>>
>> +1 by reading and testing.
>> I changed <p> to <.*?> to allow all kind of tags there (v2).
>>
>> The complete parsing of config_default is really too magic and cryptic,
>> so i like your little enhancement, as it'S really important to show the
>> meaning of the parameters very clear. Therefore html is needed to
>> structure the description.
>>
>> vg Steffen
>>
>
>
> Hi,
>
> I didn't test it and you can correct me if I'm wrong:
>
> Is it possible to insert iframes or script-tags?
>
> If yes: is it a security-issue perhaps?
Everything is possible. It is a security issue if some patch enters that
core that includes them. The whole config_default.php is not written by
anyone except the core developers. You'll have to trust us. ;)
Cheers,
Ernesto
More information about the TYPO3-team-core
mailing list