From b706456847640ce714d537e781ea59587b0f0298 Mon Sep 17 00:00:00 2001 From: Florian Pritz Date: Thu, 22 Aug 2013 18:12:54 +0200 Subject: Add comment about ID blacklist Signed-off-by: Florian Pritz --- application/models/mfile.php | 2 ++ 1 file changed, 2 insertions(+) (limited to 'application/models/mfile.php') diff --git a/application/models/mfile.php b/application/models/mfile.php index f992a0891..fe762d954 100644 --- a/application/models/mfile.php +++ b/application/models/mfile.php @@ -21,6 +21,8 @@ class Mfile extends CI_Model { static $id_blacklist = NULL; if ($id_blacklist == NULL) { + // This prevents people from being unable to access their uploads + // because of URL rewriting $id_blacklist = scandir(FCPATH); $id_blacklist[] = "file"; $id_blacklist[] = "user"; -- cgit v1.2.3-24-g4f1b