Skip to content

[BUGFIX] Security improvements, error handling, and data calculation fixes - #16

Open
froemken wants to merge 6 commits into
mainfrom
fixSecurityAndStability
Open

froemken wants to merge 6 commits into
mainfrom
fixSecurityAndStability

Conversation

@froemken

@froemken froemken commented Sep 6, 2026

Copy link
Copy Markdown
Owner

Summary of Changes

  • External IP Retrieval: Switched from blocking file_get_contents('http://...') to TYPO3 GeneralUtility::getUrl(self::EXTERNAL_IP_URL) using HTTPS with configurable constant.
  • Password Decryption Fallback: Extracted password resolution into resolvePassword() in PleskClientFactory to prevent Undefined variable $password runtime error if decryption fails.
  • Plesk Session Security: Restricted the direct "Login to Plesk" session button in ServerWidget to TYPO3 administrator backend users to avoid privilege escalation for non-admin editors.
  • DataHandlerHook Fix: Allowed nullable ?array &$incomingFieldArray parameter in DataHandlerHook to prevent fatal TypeError when invalidating records during password policy validation.
  • Webspace Calculation & Units: Fixed operator precedence when calculating free disk space in WebspaceDataProvider and integrated DisplayUnit enum with getLabel() method for uppercase chart titles (MB, GB, %).
  • Cache Scoping: Scoped runtime cache identifier in PleskSiteService by server protocol, host, and port to avoid cache collisions across multiple Plesk server records.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant