Now that we have fixed the usage of authorize.php when using Installer module for manual module installs (#1920), it's become clear that we should be using authorize.php for all downloading/installing of modules/themes/layouts.
Without using authorize.php, Installer module only works if the owner of web root directory and the web server user are the same. By using authorize.php, we could enable users to more securely set up their site and still allow modules to be downloaded/installed. If the owner of the web root is the web server user (as is the case in most shared hosting environments and Pantheon), then we don't have a problem. But when these users are different, authorize.php could enable the use of the Installer UI.
Recent comments
Funnily we launched a new Dutch website this very week, milieucafe.nl It is not a 'news' website but operates in the context of local government. The layout focuses on content instead of...
Looking for examples of (local) news websites running on BackdropCMS
The answer is off topic, but I'll add a little. 1. Backend. Why you don't need links to other websites: Since you know the structure of your site and content, you can decide for...
Looking for examples of (local) news websites running on BackdropCMS
Hi Chrys, AI isn't always your best friend. A form alter hook is correct, but hiding by CSS isn't ideal. You could look at how the TinyMCE integration does it, which provides hiding...
CKEditor5: Here's how to prevent "Select Image from Library" from appearing