Project

General

Profile

Actions

Bug #83258

closed

Close-button in edit-popups directly references HTML in Resources/Private

Added by Sven Juergens over 6 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Must have
Category:
Backend User Interface
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
8
PHP Version:
Tags:
Complexity:
easy
Is Regression:
Sprint Focus:

Description

hi,

i have a fresh install of TYPO3 8.7.8 and use the standard .htaccess file from the typo3_src folder.

but in this htaccess is this line

RewriteRule (?:typo3conf/ext|typo3/sysext|typo3/ext)/[^/]+/(?:Configuration|Resources/Private|Tests?|Documentation|docs?)/ - [F]

which blocks access to all Resource/Private Folders.

if you use feedit (not frontend_editing) the contentelements will be opened in PopUps. BUT the Close Button (next to the save Button) got a returnURL with

typo3/sysext/backend/Resources/Private/Templates/Close.html

so you can save you content Element but if you click close Button you got a 403 Forbidden Error


Files

forbidden.mp4 (127 KB) forbidden.mp4 Sven Juergens, 2017-12-08 10:20
forbidden-in-be.mp4 (210 KB) forbidden-in-be.mp4 Sven Juergens, 2017-12-08 10:49
openInNewWindow.png (2.31 KB) openInNewWindow.png Stephan Großberndt, 2017-12-08 11:54

Related issues 2 (0 open2 closed)

Follows TYPO3 Core - Task #68108: Move close.html to ext:backendClosed2015-07-14

Actions
Precedes TYPO3 Core - Task #83284: Remove EXT:backend/Resources/Private/Templates/Close.htmlClosedStephan Großberndt2017-12-11

Actions
Actions

Also available in: Atom PDF