{"id":354,"date":"2011-09-03T11:39:47","date_gmt":"2011-09-03T11:39:47","guid":{"rendered":"http:\/\/www.sitekickr.com\/blog\/?p=354"},"modified":"2011-09-03T11:40:13","modified_gmt":"2011-09-03T11:40:13","slug":"mvc-security-issue","status":"publish","type":"post","link":"https:\/\/www.sitekickr.com\/blog\/mvc-security-issue\/","title":{"rendered":"MVC security issue"},"content":{"rendered":"<p>Using the model-view-controller approach is a great way to organize your code and keep logic separate from presentation, but depending on the framework you use, being custom or otherwise, you might be exposed to security issue.<\/p>\n<p>If your web server isn&#39;t configured properly to disallow direct serving of model or view files, you could be exposed to a very big security hole.<\/p>\n<p>Let&#39;s say that your model code contains validation which would normally disallow a user from proceeding to the view code. If your view code contains a database table update, your user could simply call the view script directly.<\/p>\n<p>If you aren&#39;t protected by denying access at the web server level, you may need to check for the existence of a variable created in the model file within the view file.<\/p>\n<p><strong>Model<\/strong><br \/>\n\tvalidate the user<br \/>\n\tvalidated = true<\/p>\n<p><strong>View\/Action<\/strong><br \/>\n\tif not validated:<br \/>\n\t&nbsp;&nbsp;&nbsp; abort<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Using the model-view-controller approach is a great way to organize your code and keep logic separate from presentation, but depending on the framework you use,&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"amp_status":""},"categories":[123],"tags":[293],"_links":{"self":[{"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/posts\/354"}],"collection":[{"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/comments?post=354"}],"version-history":[{"count":0,"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/posts\/354\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/media?parent=354"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/categories?post=354"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sitekickr.com\/blog\/wp-json\/wp\/v2\/tags?post=354"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}