October 5, 201016 yr Hi guys, In codeigniter, is it necessary to block access to files (views, controllers etc.) you create using define('VariableHere', TRUE); and if(!defined('VariableHere'){die('Direct access not permitted');} (or .htaccess or similar etc etc.), or does CI automatically handle this? Cheers! Martin
October 5, 201016 yr Your application directory should be outside of the web root so its not necessary.
October 6, 201016 yr Jock can you explain how you would do that? Would you just leave the index.php file in the web root? Codeigniter has index.html files in the root of each folder, which stops indexes showing. But I use: <?php if ( ! defined('BASEPATH')) exit('No direct script access allowed'); ?> at the start of each file, it seems to do the trick. (It's what all codeigniter system files have as well) Hope it helps
October 6, 201016 yr I'm no expert, I've only made one code igniter site, but I just put the system_folder outside of the web root. Then defined it in the index.php file as '../system'. This is standard practice with Zend Framework.
October 6, 201016 yr Author Thanks Jock. @asek - yeah, I looked at all the CI files and have started putting <?php if ( ! defined('BASEPATH')) exit('No direct script access allowed'); ?> in the header of all my files. As of CodeIgniter 2.0, the application directory is outside the system directory by default as well, so I guess it's best practice to put both outside htdocs. M
Create an account or sign in to comment