[TYPO3-core] RFC #14719: Automatically create ENABLE_INSTALL_TOOL file when 1-2-3 Install Tool is used

Martin Kutschker masi-no at spam-typo3.org
Tue Jun 15 09:50:30 CEST 2010


Dmitry Dulepov schrieb:
> Hi!
> 
> Jeff Segars wrote:
>> Problem:
>> When a new user first installs TYPO3, they must create the
>> ENABLE_INSTALL_TOOL file before installation can continue. For a
>> friendlier first install, it would be nice to automatically create the
>> file and go directly to the 1-2-3 Install Tool
> 
> This may cause security issues. The most obvious is when the site is in
> prepared but not yet installed. If it is left like this, anybody from the
> Internet will be able to access Install tool.
> 
> I insist that it must be evaluated by the security team before it is committed.

And I suggest that the whole installer handling has to be changed in 4.5. IMHO no code in the main
processing (tslib_fe in particular) should have to deal with a detail of the installation process.

Anyway I hope we can find a way that is both user friendly and secure.

Masi


More information about the TYPO3-team-core mailing list