Project

General

Profile

Actions

Bug #52634

closed

sys_categories are missing security restrictions

Added by Steffen Ritter over 10 years ago. Updated almost 8 years ago.

Status:
Rejected
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2013-10-12
Due date:
% Done:

100%

Estimated time:
(Total: 0.00 h)
TYPO3 Version:
6.2
PHP Version:
Tags:
Complexity:
Is Regression:
No
Sprint Focus:

Description

Like tt_news or ext news categories need to be restrictable for backend users.

- selection for groups and users
- TCA tree must respect this selection
- TCEmain must check that selecting not allowed categories is not posible,
- TCEmain must check that categories, already set by others before, but not allowed for me, are not removed on saving.


Subtasks 1 (0 open1 closed)

Feature #52718: Restrict visibility of Category for a BE UserClosed2013-10-12

Actions

Related issues 1 (0 open1 closed)

Related to TYPO3 Core - Bug #71461: CategoryPermissionsAspect does not check changed rootUid of treeRejected2015-11-10

Actions
Actions #1

Updated by Stefan Neufeind about 10 years ago

What is left here? The TCEmain-part?

Actions #2

Updated by Steffen Ritter about 10 years ago

yes

Actions #3

Updated by Thierry Brodard about 10 years ago

Actually, on the 6.2 RC1, the category-tree is filtered for files, but not in the list-module: even if a category mount is set for a be-group, all be-users can see all categories.

Actions #4

Updated by Lorenz Ulrich almost 10 years ago

How would you handle category restriction for different records. If e.g. news, tt_address and FAL are using the Category API, you might have categories that are News-only, categories that are tt_address only etc.. For the user it will be distracting if he can add a category meant for addresses to a News item.

Maybe it would be nice if categories could be locked to record types (default to all). What do you think?

Actions #5

Updated by Mathias Schreiber over 8 years ago

  • Target version deleted (6.2.0)
Actions #6

Updated by Christian Kuhn almost 8 years ago

  • Status changed from New to Rejected

very hard to resolve, will not be done in near future, see related https://forge.typo3.org/issues/71461

Actions

Also available in: Atom PDF