TYPO3-Documentation / TYPO3CMS-Reference-CoreApi

"TYPO3 Explained": Main TYPO3 Core Document: Main classes, Security, TypoScript syntax, Extension API and much more
https://docs.typo3.org/m/typo3/reference-coreapi/master/en-us/
22 stars 383 forks source link

Note for Security "Content Elements" has vague notice "outdated" without further information #2768

Open sypets opened 1 year ago

sypets commented 1 year ago

The information on this page is outdated!

https://docs.typo3.org/m/typo3/reference-coreapi/main/en-us/Security/GuidelinesIntegrators/ContentElements.html

What is outdated? How can we fix it?

(I assume the RTE propressing already removes some problematic HTML elements when the ce is saved, but have to check first).

Also, I think we should be much more clear about what is recommend and what is not in simple short sentences, e.g. a box / note at the top:

Recommended:

* disable the HTML element or at least disable it for non admins
* ...
DavidBruchmann commented 1 year ago

The information is so far outdated as essential RTE configuration is done by yaml files now.
Some of the old options in TSconfig are still available but many are gone and not advised anymore for general configuration.
Some links are here:
https://docs.typo3.org/m/typo3/reference-coreapi/main/en-us/ApiOverview/Rte/RteCkeditorSysext.html and then naturally in the linked document is the important information.