Home » Forum
NoNumber!

Joomla! extensions & websites
development / support / consultancy

I try to respond within 24 hours (excluding weekends). If I haven't responded by then, feel free to post a reminder or bug me via email.
Welcome, Guest
Please Login or Register.    Lost Password?

Security Question
(1 viewing) (1) Guest
Go to bottomPage: 1
TOPIC: Security Question
#6614
Security Question 7 Months, 2 Weeks ago  
We are using sourcerer pretty extensively on a site we are developing. It's been a really great tool and made a lot of customization possible. Thanks.

I did have a question about sourcerer and whether or not it is safe to use in conjunction with forms. We are using RSForm Pro to generate our forms and have had to use the {source}{/source} tags inside the forms in order to achieve our ends.

The RSForm Pro program by default sanitizes all form submissions. Is there any reason to worry about this being a security issue?

Thanks.
Marc
Posts: 1
User OfflineClick here to see the profile of this user
The administrator has disabled public write access.
 
#6615
Re: Security Question 7 Months, 2 Weeks ago  
I don't see why it would be a security issue. Sourcerer is executed before the server passes the html to the browser. So for the client it makes no difference by what extension that html is created.

Unless you have some php code that does dangerous things with variables sent by the form (get/post), it shouldn't be a problem. But then it is your code that is an issue, not Sourcerer.
Peter van Westen
Admin
Posts: 4533
User OfflineClick here to see the profile of this user
The administrator has disabled public write access.
Need to contact me directly? Go to my contact page.
If you use any NoNumber! extensions, please post a rating and a review at the Joomla! Extensions Directory.
Are you happy with the support? Please consider buying a License Code to help me to continue development and support.
 
Go to topPage: 1
Joomla Open Source Training