Project

General

Profile

Actions

Bug #95344

open

Backend admins that also have groups assigned see the full page tree AND(!) the mount points

Added by Stefan P over 2 years ago. Updated over 2 years ago.

Status:
Needs Feedback
Priority:
Should have
Assignee:
-
Category:
Pagetree
Target version:
-
Start date:
2021-09-24
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
10
PHP Version:
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

Steps to reproduce:

  • Create a non-admin backend user with some groups that have do_mountpoints . This user sees these mountpoints. Fine.
  • Now make this user an admin without removing his groups: The user will have the full page tree and the stripped-down page tree from the groups.

If a user is admin the db_mountpoints evaluation should not happen at all (for a clean pagetree and for performance reasons).

Discovered on v9, but probably valid also on later versions.


Related issues 1 (1 open0 closed)

Related to TYPO3 Core - Feature #25381: Option to disable double listing of DB mountsNew2011-03-23

Actions
Actions

Also available in: Atom PDF