[SECURITY] Respect permissions of storages in a file collection 94/53894/2
authorGeorg Ringer <georg.ringer@gmail.com>
Tue, 5 Sep 2017 09:36:29 +0000 (11:36 +0200)
committerOliver Hader <oliver.hader@typo3.org>
Tue, 5 Sep 2017 09:36:30 +0000 (11:36 +0200)
commit9d429b0a156d30d990ff090fda446c2cab3c0f66
treec7677f320e695b3034edf49d770b2f5053ce9f9f
parente08b48fcf726b8d836e1298d5f716ef178889077
[SECURITY] Respect permissions of storages in a file collection

If a user creates a sys_file_collection record, only those
storage records must be shown which are allowed for the
user.

Resolves: #82029
Releases: master, 8.7, 7.6
Security-Commit: 3434e003fe61229e099fb80328ceda58e52c2eb0
Security-Bulletin: TYPO3-CORE-SA-2017-005
Change-Id: I41ea240e36b2a2834d385836477958652b3116a8
Reviewed-on: https://review.typo3.org/53894
Reviewed-by: Oliver Hader <oliver.hader@typo3.org>
Tested-by: Oliver Hader <oliver.hader@typo3.org>
typo3/sysext/backend/Classes/Form/FormDataProvider/AbstractItemProvider.php
typo3/sysext/backend/Classes/Form/FormDataProvider/TcaSelectItems.php
typo3/sysext/core/Classes/Resource/Service/UserFileMountService.php