News:

Join the Facebook Fan Page.

Main Menu

Is $board safe in source

Started by nwoGeo, December 18, 2013, 09:18:55 AM

Previous topic - Next topic

nwoGeo

I tried countless ways and mods to remove index.php from the homepage url and nav links. None of them worked, even some suggestions here. I couldn't avoid the white screen on first load, among other bug problems. So, I figured out to use $board instead of $scripturl. It even fixed a problem I had, where another domain was loading my site.

I've been debugging all night, no problems.

So, is calling $board safe, since some source changes were made with it?
New World Order Forum - Anti-totalitarian

Kindred

no.


Why are you trying to remove index.php from the URL?


EVERYTHING in the system descends form that point....
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

nwoGeo

If no, why not?  :o

You can see it in practice here: http://nwoforum.com

I've yet encountered a problem. Just want the technical's on what security issues I could encounter.

Why? Choice, I want things to look a certain way on site and search.
New World Order Forum - Anti-totalitarian

Kindred

you will encouner NUMEROUS errors throughout the system by trying to remove index.php from the URL and it serves no perceivable benefit.
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

nwoGeo

I explained, that I spent the last 6 or so hours checking every function/feature and everything works without error. No debug errors, white screen, etc.

Just want to make sure I haven't created a security issue by using $board instead of $scripturl. If so, what risks it posses.
New World Order Forum - Anti-totalitarian

Arantor

No, no security issue but there are times that things WILL break. Don't do it.

nwoGeo

Quote from: Arantor Beeblebrox the First on December 18, 2013, 09:46:31 AM
No, no security issue but there are times that things WILL break. Don't do it.

Thanks, what, when and how will it break?

I ask, because I can fix it or remedy the problem now, rather than later. As of now nothing's broken, what will it break?
New World Order Forum - Anti-totalitarian

Arantor

No, I'm sorry, our advice ends at "if you change a fundamental part of SMF, it will break" if we wanted to support removing index.php from the URL, we would fix the various strange and exciting bugs that result. Except we don't because of the other consequences that emerge.

nwoGeo

Quote from: Arantor Beeblebrox the First on December 18, 2013, 10:00:36 AM
No, I'm sorry, our advice ends at "if you change a fundamental part of SMF, it will break" if we wanted to support removing index.php from the URL, we would fix the various strange and exciting bugs that result. Except we don't because of the other consequences that emerge.

Alright, cool I'll just keep you all posted if something breaks. If it does, it's pretty simple to revert back anyway. Good to know no security problems though.
New World Order Forum - Anti-totalitarian

Arantor

And the first thing we will tell you if you report issues that relate to it is to undo it.

nwoGeo

Quote from: Arantor Beeblebrox the First on December 18, 2013, 10:22:19 AM
And the first thing we will tell you if you report issues that relate to it is to undo it.

Understood, but really I doubt I will. You guys should really work on removing it, index.php as a homepage canonical is not appealing for sites that are just a forum/portal. Especially if you make simpleportal a front page. Other platforms rarely use it, and no major social company uses that format. It would be a great way to evolve to current standards.

This website doesn't use index.php for the homepage, so that goes to tell you it's preferred.
New World Order Forum - Anti-totalitarian

Arantor

I love being told what I 'should' do in my spare time.

nwoGeo

Quote from: Arantor Beeblebrox the First on December 18, 2013, 10:45:01 AM
I love being told what I 'should' do in my spare time.
Sorry, I didn't mean to offend. If I came off like that, my fault.
New World Order Forum - Anti-totalitarian

Kindred

#13
This website does not use the forum for its front page.....
Our homepage is supplied via SSI and custom scripts...


And as for "appealing" -- once someone gets to the site, they don't CARE what the URL is...   if the base URL points to the site, they are good. If it loads index.php as part of the url after that, 99% of them won't even notice.


And your PERCEPTION does not make something a "standard".
There are no internet STANDARDS which indicate that the presence or lack of index.php is correct or not.
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

nwoGeo

What I meant by "standard," is that majority of websites homepage is their domain name dot com, including just forum sites. Like I mentioned above, it's all about choice and theirs nothing wrong with providing that.
New World Order Forum - Anti-totalitarian

Arantor

And that works just fine. No sense fixing what isn't broken.

nwoGeo

New World Order Forum - Anti-totalitarian

Kindred

also...   blah dot com works just fine for SMF forums...   it gets you to the site. The forum recognizes the incoming connection and then adds th eindex.php in the future navigations through the site...   and as I said, 99% of the users never even look at the URL once they get to the site.

So your perception of a standard is skewed...   because dot com WORKS to get to the site and DOESN'T MATTER after that.


(and I will note...  this is the sort of thing that I do for a paying job IRL)
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

nwoGeo

This topic has been solved, and theirs no sense in arguing over what "DOESN'T MATTER," different things matter to different people. Case in point, If I wasn't able to remove it, I would have switched to another free platform. That's how much it mattered to me.
New World Order Forum - Anti-totalitarian

Advertisement: