---
title: "Feature: #110863 - Improved configuration of public backend routes"
manual: "TYPO3 Core Changelog"
version: "main"
permalink: "https://docs.typo3.org/permalink/changelog:feature-110863-1790781220"
source: "Changelog/15.0/Feature-110863-ImprovedConfigurationOfPublicBackendRoutes.rst"
typo3-version: "15.0"
typo3-major: 15
type: "feature"
issue: 110863
forge: "https://forge.typo3.org/issues/110863"
tags: ["Backend", "PHP-API", "ext:backend"]
rendered: "2026-10-07T19:18:07+00:00"
---

# Feature: #110863 - Improved configuration of public backend routes {#feature-110863-1790781220}

See [forge#110863](https://forge.typo3.org/issues/110863)

## Description {#description}

Whether a backend route can be reached without a backend user has been
defined in two independent places: a hardcoded list of paths in
`\TYPO3\CMS\Backend\Middleware\BackendUserAuthenticator` and the route
option `access`, which only controlled the request token. Both
definitions had diverged, for example for the route
`ajax_login_refresh`.

The route option `access` is now the single source of truth. It is backed
by the new enum `\TYPO3\CMS\Backend\Routing\RouteAccess` and accepts
the values:

-   `anonymous`: The route can be reached without a backend user and
    without a request token, for example the login or the password reset.
-   `authenticated` (default): The route requires a backend user and a
    valid request token.
-   `authenticated-without-token`: The route requires a backend user, but
    no request token.

Extensions can use `anonymous` for routes that must be reachable
without a session, for example callback endpoints of single sign-on
implementations:

**EXT:my_extension/Configuration/Backend/Routes.php**

```php
return [
    'my_sso_callback' => [
        'path' => '/my-extension/sso/callback',
        'access' => 'anonymous',
        'target' => SsoCallbackController::class . '::handleRequest',
    ],
];
```

Any other value of `access` is treated as `authenticated`, so a
misspelled value can never expose a route. The class
`\TYPO3\CMS\Backend\Routing\Route` provides the new method
`getAccess()`, which returns the `RouteAccess` with the methods
`requiresAuthentication()` and `requiresRequestToken()`.

Additionally, the new backend middleware
`\TYPO3\CMS\Backend\Middleware\FetchMetadataGuard` rejects
state-changing requests (any method except `GET`, `HEAD` and
`OPTIONS`) to non-anonymous routes with a `403` response, if the
browser reports them as `cross-site` or `same-site` via the
`Sec-Fetch-Site` header. If the header is missing, the `Origin`
header is compared with the host of the request. The middleware can be
disabled with the feature toggle
`$GLOBALS['TYPO3_CONF_VARS']['SYS']['features']['security.backend.enforceFetchMetadata']`.

The CLI command `typo3 debug:backend:routes` now lists the access and
the request token requirement of each route and can be filtered with the
new option `--access`, for example `--access=anonymous`.

## Impact {#impact}

Extensions can register backend routes that are processed without a backend
user by using `'access' => 'anonymous'`. The routes
`ajax_login_refresh`, `state-tracker` and `language_domain`
are now declared consistently.

The route access `public` has been deprecated, see
[Deprecation: #110863 - Backend route access "public"](https://docs.typo3.org/permalink/changelog:deprecation-110863-1790766913).

Backend requests, which change data and originate from another site, are now
denied by default.
