Feature: #110863 - Improved configuration of public backend routes
See forge#110863
Description
Whether a backend route can be reached without a backend user has been
defined in two independent places: a hardcoded list of paths in
\TYPO3\ and the route
option
access
, which only controlled the request token. Both
definitions had diverged, for example for the route
ajax_.
The route option
access
is now the single source of truth. It is backed
by the new enum
\TYPO3\ and accepts
the values:
anonymous: The route can be reached without a backend user and without a request token, for example the login or the password reset.authenticated(default): The route requires a backend user and a valid request token.authenticated-: The route requires a backend user, but no request token.without- token
Extensions can use
anonymous
for routes that must be reachable
without a session, for example callback endpoints of single sign-on
implementations:
return [
'my_sso_callback' => [
'path' => '/my-extension/sso/callback',
'access' => 'anonymous',
'target' => SsoCallbackController::class . '::handleRequest',
],
];
Any other value of
access
is treated as
authenticated
, so a
misspelled value can never expose a route. The class
\TYPO3\ provides the new method
get, which returns the
Route with the methods
requires and
requires.
Additionally, the new backend middleware
\TYPO3\ rejects
state-changing requests (any method except
GET
,
HEAD
and
OPTIONS
) to non-anonymous routes with a 403 response, if the
browser reports them as
cross- or
same- via the
Sec- header. If the header is missing, the
Origin
header is compared with the host of the request. The middleware can be
disabled with the feature toggle
$GLOBALS.
The CLI command
typo3 debug: now lists the access and
the request token requirement of each route and can be filtered with the
new option
--, for example
--.
Impact
Extensions can register backend routes that are processed without a backend
user by using
'access' => 'anonymous'
. The routes
ajax_,
state- and
language_
are now declared consistently.
The route access
public
has been deprecated, see
Deprecation: #110863 - Backend route access "public".
Backend requests, which change data and originate from another site, are now denied by default.