Skip to content
GitLab
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Sign in
  • T TYPO3.CMS
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Locked Files
  • Issues 0
    • Issues 0
    • List
    • Boards
    • Service Desk
    • Milestones
    • Iterations
    • Requirements
  • Merge requests 8
    • Merge requests 8
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
    • Test Cases
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Infrastructure Registry
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Code review
    • Insights
    • Issue
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • accessibilityaccessibility
  • TYPO3.CMS
  • Repository
Switch branch/tag
  • TYPO3.CMS
  • typo3
  • sysext
  • backend
  • Classes
  • Controller
  • BackendController.php
Find file BlameHistoryPermalink
  • Wouter Wolters's avatar
    [SECURITY] Prevent persistent username in filesystem · 93ce2867
    Wouter Wolters authored Jul 19, 2016 and Oliver Hader's avatar Oliver Hader committed Jul 19, 2016
    The language label for the refresh login popup contains the
    username already and is persisted to the filesystem. Use
    TYPO3.configuration.username and replace it with JavaScript
    instead to prevent the information disclosure.
    
    Resolves: #75933
    Releases: master, 7.6, 6.2
    Security-Commit: 0e7b21b3f455fef6703656889c43993976a4a6bc
    Security-Bulletins: TYPO3-CORE-SA-2016-014, 015, 016, 017, 018
    Change-Id: I14964781014b95d9753ad8d6ed79df5f25c1fa5c
    Reviewed-on: https://review.typo3.org/49081
    
    
    Reviewed-by: Oliver Hader's avatarOliver Hader <oliver.hader@typo3.org>
    Tested-by: Oliver Hader's avatarOliver Hader <oliver.hader@typo3.org>
    93ce2867