[TYPO3-core] RFC #14935: Install tool password can be overwritten by an extensions' ext_localconf.php

Benjamin Mack benni at typo3.org
Tue Jan 4 10:47:33 CET 2011


Hey,

this is a SVN patch request.

Branch: trunk only

Type: security feature

Bt reference: http://bugs.typo3.org/view.php?id=14935

Problem:
The Install Tool Password can be changed by any extension that is
installed. It should only be changeable in localconf.php

Solution:
Use a constant instead of the variable - throughout the Core.

All the best,
benni.


More information about the TYPO3-team-core mailing list