Feature: #110863 - Improved configuration of public backend routes 

See forge#110863

Description 

Whether a backend route can be reached without a backend user has been defined in two independent places: a hardcoded list of paths in \TYPO3\CMS\Backend\Middleware\BackendUserAuthenticator and the route option access , which only controlled the request token. Both definitions had diverged, for example for the route ajax_login_refresh .

The route option access is now the single source of truth. It is backed by the new enum \TYPO3\CMS\Backend\Routing\RouteAccess and accepts the values:

  • anonymous : The route can be reached without a backend user and without a request token, for example the login or the password reset.
  • authenticated (default): The route requires a backend user and a valid request token.
  • authenticated-without-token : The route requires a backend user, but no request token.

Extensions can use anonymous for routes that must be reachable without a session, for example callback endpoints of single sign-on implementations:

EXT:my_extension/Configuration/Backend/Routes.php
return [
    'my_sso_callback' => [
        'path' => '/my-extension/sso/callback',
        'access' => 'anonymous',
        'target' => SsoCallbackController::class . '::handleRequest',
    ],
];
Copied!

Any other value of access is treated as authenticated , so a misspelled value can never expose a route. The class \TYPO3\CMS\Backend\Routing\Route provides the new method getAccess() , which returns the RouteAccess with the methods requiresAuthentication() and requiresRequestToken() .

Additionally, the new backend middleware \TYPO3\CMS\Backend\Middleware\FetchMetadataGuard rejects state-changing requests (any method except GET , HEAD and OPTIONS ) to non-anonymous routes with a 403 response, if the browser reports them as cross-site or same-site via the Sec-Fetch-Site header. If the header is missing, the Origin header is compared with the host of the request. The middleware can be disabled with the feature toggle $GLOBALS['TYPO3_CONF_VARS']['SYS']['features']['security.backend.enforceFetchMetadata'] .

The CLI command typo3 debug:backend:routes now lists the access and the request token requirement of each route and can be filtered with the new option --access , for example --access=anonymous .

Impact 

Extensions can register backend routes that are processed without a backend user by using 'access' => 'anonymous' . The routes ajax_login_refresh , state-tracker and language_domain are now declared consistently.

The route access public has been deprecated, see Deprecation: #110863 - Backend route access "public".

Backend requests, which change data and originate from another site, are now denied by default.