ADR-003: Security Responsibility Boundaries
- Date
-
2025-12-14
- Status
-
Accepted
- Context
-
Code Review v13.0.1 → v13.2.x
Summary
This ADR documents the security responsibility boundaries between this extension
(netresearch/) and TYPO3 Core. Clear boundaries prevent
scope creep and ensure security issues are addressed by the appropriate party.
Decision
The following security responsibilities are explicitly out of scope for this extension and are delegated to TYPO3 Core:
Out of Scope (TYPO3 Core Responsibility)
-
SVG Sanitization
- SVG files can contain embedded JavaScript (
<script>tags, event handlers) - TYPO3 FAL is responsible for validating and sanitizing uploaded SVG files
- This extension only references files already accepted by TYPO3
- Related issue: #474 tracks optional additional protection, but Core sanitization is primary defense
- SVG files can contain embedded JavaScript (
-
File Extension / MIME Type Validation
- Ensuring a file's extension matches its actual content type
- Example: Blocking a
.jpgfile that contains SVG/XML content - TYPO3 FAL validates this during upload via
Fileand MIME checksName Validator - This extension trusts FAL's validation when referencing
sys_recordsfile
-
General File Upload Security
- Virus scanning, file size limits, allowed extensions
- All handled by TYPO3 FAL and
$GLOBALS['TYPO3_ CONF_ VARS'] ['BE'] ['file Deny Pattern']
-
Image Processing Security
- ImageMagick/GraphicsMagick command injection prevention
- Handled by TYPO3's
GraphicalandFunctions ImageService
In Scope (This Extension's Responsibility)
-
Caption XSS Prevention
- User-editable caption text must be sanitized
- Implementation:
htmlspecialchars($caption, ENT_ QUOTES | ENT_ HTML5, 'UTF- 8') - Location:
ImageResolver Service:: sanitize Caption ()
-
File Visibility Validation
- Prevent rendering images from non-public storages
- Backend users should not expose internal files via RTE
- Location:
ImageResolver Service:: validate File Visibility ()
-
Dangerous Protocol Blocking
- Block
javascript:,vbscript:,data:in URLstext/ html - Tracked in #475
- Location:
ImageResolver Service:: DANGEROUS_ PROTOCOLS
- Block
-
SSRF Protection for External Images
- DNS rebinding prevention
- Private/reserved IP blocking
- Cloud metadata endpoint blocking
- Location:
RteImages Db Hook:: get Safe Ip For External Fetch ()
-
Style Attribute Exclusion
- Prevent CSS injection via style attributes
- Style attributes are explicitly excluded from
htmlAttributes - Location:
ImageResolver Service:: build Html Attributes ()
-
SVG Data URI Sanitization
- Sanitize embedded JavaScript in
data:URIsimage/ svg+xml - Removes
<script>tags, event handlers (onload,onerror, etc.), andjavascript:hrefs - Uses TYPO3 Core's
Svgfor consistency with FAL sanitizationSanitizer - Location:
ImageResolver Service:: sanitize Svg Data Uri () - Addresses: #474
- Sanitize embedded JavaScript in
-
External-link rel security (Fluid path)
- Append
rel="noreferrer"ontarget="_external links in the figure-wrapped Fluid render path, mirroring TYPO3'sblank" LinkFactory:: add Security Rel Values () - In scope because the Fluid
Link.partial constructshtml <a>directly and does not go throughLink, so Core's security helper never executes on this pathFactory - Preserves any pre-existing
reltokens (nofollow,sponsored,noopener); appendsnoreferrerat most once - Location:
Service\\, wired inSecurity Rel Computer:: compute () Service\\andImage Resolver Service:: build Link Dto () createDto From External Image () - Addresses: #799
- Append
Known Boundaries & Limitations
-
Data URI Handling
Data URIs (
data:) bypass FAL upload validation entirely since they are embedded inline rather than uploaded as files. Security measures are in place:image/* - Blocked:
data:,text/ html javascript:,vbscript:,file:protocols - Allowed:
data:for legitimate inline images (Base64-encoded)image/* - Sanitized:
data:content is passed through TYPO3'simage/ svg+xml Svgto remove embedded JavaScript (Sanitizer <script>tags, event handlers,javascript:hrefs)
Rationale: Blocking all data URIs would break legitimate use cases (copy/paste images from clipboard). SVG data URIs are now sanitized at render time using the same sanitizer that TYPO3 FAL uses for uploaded SVG files, providing consistent protection regardless of how the SVG content was introduced.
- Blocked:
-
Frontend Context Processing
The
Rteskips processing in frontend contexts rather than throwing exceptions. This ensures DataHandler operations triggered from frontend (e.g., frontend editing extensions, TypoScript-based content manipulation) do not crash.Images Db Hook - Images in frontend-saved content retain their original URLs
- Magic image processing only occurs during backend saves
- This is intentional to prevent breaking frontend editing workflows
Consequences
Positive:
- Clear accountability for security issues
- Prevents duplicate security implementations
- Reduces extension complexity by leveraging Core security
Negative:
- Relies on TYPO3 Core maintaining its security measures
- Sites with outdated TYPO3 versions may have gaps
Mitigations:
- Document minimum TYPO3 version requirements
- Optional additional protections tracked in GitHub issues (#474, #475)
- Users can enable stricter settings via extension configuration