[eluser]Kraig[/eluser]
[quote author="PhilTem" date="1356101671"]
Thus, the only plausible way would be to use some filtering in MY_Controller::__construct() to check for allowed/disallowed requests

[/quote]
Do you happen to have an example? I'm surprised this issue hasn't been looked at and fixed before. I use controller functions externally when submitting forms and when using ajax. Making them secure is a must.