[SECURITY] Extbase must not cache dynamic parts of queries
Do not cache the enable fields part of queries. This part needs to be added on each query dynamically to reflect the current context. (Time restrictions, User restrictions) Resolves: #58369 Releases: 6.2 Change-Id: I492d5983ff6a06d72cd18cf9a08a0d62d304ac2b Reviewed-on: https://review.typo3.org/29932 Reviewed-by: Wouter Wolters Tested-by: Wouter Wolters Reviewed-by: Marcin Sągol Reviewed-by: Jan Kiesewetter Tested-by: Jan Kiesewetter Reviewed-by: Georg Ringer Tested-by: Georg Ringer
Showing
- typo3/sysext/extbase/Classes/Persistence/Generic/Storage/Typo3DbBackend.php 2 additions, 0 deletions...se/Classes/Persistence/Generic/Storage/Typo3DbBackend.php
- typo3/sysext/extbase/Classes/Persistence/Generic/Storage/Typo3DbQueryParser.php 21 additions, 1 deletion...lasses/Persistence/Generic/Storage/Typo3DbQueryParser.php
Please register or sign in to comment