---
title: "Deprecation: #84326 - Protected methods and properties in FileUploadController"
manual: "TYPO3 Core Changelog"
version: "main"
permalink: "https://docs.typo3.org/permalink/changelog:deprecation-84326"
source: "Changelog/9.2/Deprecation-84326-ProtectedMethodsAndPropertiesInFileUploadController.rst"
typo3-version: "9.2"
typo3-major: 9
type: "deprecation"
issue: 84326
forge: "https://forge.typo3.org/issues/84326"
tags: ["Backend", "PHP-API", "PartiallyScanned"]
rendered: "2026-09-17T12:41:04+00:00"
---

# Deprecation: #84326 - Protected methods and properties in FileUploadController {#deprecation-84326-protected-methods-and-properties-in-fileuploadcontroller}

See [forge#84326](https://forge.typo3.org/issues/84326)

## Description {#description}

This file is about third party usage of `\TYPO3\CMS\Backend\Controller\File\FileUploadController`.

A series of class properties has been set to protected.
They will throw deprecation warnings if called public from outside:

-   `title`
-   `target`
-   `returnUrl`
-   \[not scanned\] `content`

All methods not used as entry points by `\TYPO3\CMS\Backend\Http\RouteDispatcher` will be
removed or set to protected in v10 and throw deprecation warnings if used from a third party:

-   \[not scanned\] `main()`
-   `renderUploadForm()`

Additionally `$GLOBALS['SOBE']` is not set by the `FileUploadController` constructor anymore.

## Impact {#impact}

Calling one of the above methods or accessing one of the above properties on an instance of
`FileUploadController` will throw a deprecation warning in v9 and a PHP fatal in v10.

## Affected Installations {#affected-installations}

The extension scanner will find most usages, but may also find some false positives. The most
common property and method names like `$content` are not registered and will not be found
if an extension uses that on an instance of `FileUploadController`.

In general all extensions that set properties or call methods except `mainAction()` are affected.

## Migration {#migration}

In general, extensions should not instantiate and re-use controllers of the core. Existing
usages should be rewritten to be free of calls like these.
