Commit bf604dae authored by Lina Wolf's avatar Lina Wolf Committed by Nikita Hovratov
Browse files

[DOCS] Document "Restrict export functionality"

Add changelog entry to - Restrict export functionality to allowed users

Resolves: #97771
Releases: main, 11.5, 10.4
Change-Id: I98252b73aa5b14a8cfe5d26559711123e17ced15

Tested-by: core-ci's avatarcore-ci <>
Tested-by: Nikita Hovratov's avatarNikita Hovratov <>
Reviewed-by: Nikita Hovratov's avatarNikita Hovratov <>
parent a1dafd40
.. include:: /Includes.rst.txt
.. _important-94951-1655368664:
Important: #94951 - Restrict export functionality to allowed users
See :issue:`94951`
.. important::
This change was introduced as part of the
`TYPO3 11.5.11 and 10.4.29 security release <>`__.
The export functionality has the following security drawbacks:
* Export for editors is not limited on field level
* The :guilabel:`Save to filename` functionality saves to a shared folder,
which other editors with different access rights may have access to.
Both issues are not easy to resolve and also the target
audience for the Import/Export functionality are mainly
TYPO3 admins.
The export functionality is restricted
to TYPO3 admin users and to users, who explicitly have
access through the new user TSConfig setting
Affected installations
Installations with EXT:impexp installed where non-admin users need to use the
export functionality.
If non-admin users should be able to use the export tool, set the
following user TSconfig:
.. code-block:: typoscript
:caption: EXT:my_sitepackage/Configuration/TSconfig/allusers.tsconfig
options.impexp.enableExportForNonAdminUser = 1
.. index:: Backend, TSConfig, NotScanned, ext:impexp
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment