Filter by URL: really OK to show table name?

boyjah

Member
I want to make a bunch of different links that filter a list. I have read through the rather confusing WIKI article about this and have got it to work, but I am apprehensive about showing the full database table name in the URL. Doesn't that pose a security risk? Isn't that why JOOMLA advises us to create a random prefix for our database name, to make it difficult for troublemakers to gain unauthorized access to our databases? Is there any other way to create a filter link that does not require including the datatable name? Isn't the list id sufficient for Fabrik to know which data table the variable we want to use is in?
 
Is there any other way to create a filter link that does not require including the datatable name in the URL?
 
If you want different filtered links, you can create multiple Fabrik list menu items, and set prefilters in the menu item settings for the list.

Sent from my HTC6545LVW using Tapatalk
 
And to answer your question, it's debatable whether exposing specific table names is a real risk. The main issue with Joomla table names was guarding against generic attacks, where hackers are just trying to break into any site they can find, and having all Joomla sites use jos_ as the prefix made it much easier.

Regardless of whether you use element names in links, any Fabrik page will have element names in the page source, so you don't gain much by not using them in link filters.

Sent from my HTC6545LVW using Tapatalk
 
We are in need of some funding.
More details.

Thank you.

Members online

Back
Top