[TYPO3-core] Access denied for old security bug

Christian Weiske christian.weiske at netresearch.de
Wed Jun 19 17:13:47 CEST 2013


Helmut and Dmitry,


> > The fix: https://review.typo3.org/#/c/21501/
> 
> Nice idea to do it this way, unfortunately, this would introduce a 
> severe security problem. Please read my comment in Gerrit.

Could you please describe why you insist on verifying the OpenID URL
before starting the OpenID login process?

-- 
Regards/Mit freundlichen Grüßen
Christian Weiske

-= Geeking around in the name of science since 1982 =-



More information about the TYPO3-team-core mailing list