• 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
URL disallowed characters with routes

#1
[eluser]Unknown[/eluser]
Hey, I had just a question about changing this in the config.php file.
Code:
$config['permitted_uri_chars'] = 'a-z 0-9~%.:_\-';
to
Code:
$config['permitted_uri_chars'] = '';
I know this is a security risk, but what if my routes is like this
Code:
$route['default_controller'] = "home";
$route[':any'] = "avatar/execute";
Will it be safe since the url will not point at any class or function?
If not, what characters is a security risk?

Thank you for your answers!

#2
[eluser]keithics[/eluser]
$route[':any'] = "avatar/execute"; -> is like having the default controller (not tested it though). And why would you do that?


Digg   Delicious   Reddit   Facebook   Twitter   StumbleUpon  


  Theme © 2014 iAndrew  
Powered By MyBB, © 2002-2021 MyBB Group.