security.html 44 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663
  1. <!DOCTYPE html>
  2. <!--[if IE 8]><html class="no-js lt-ie9" lang="en" > <![endif]-->
  3. <!--[if gt IE 8]><!--> <html class="no-js" lang="en" > <!--<![endif]-->
  4. <head>
  5. <meta charset="utf-8">
  6. <meta name="viewport" content="width=device-width, initial-scale=1.0">
  7. <title>Security &mdash; CodeIgniter 3.1.11 documentation</title>
  8. <link rel="shortcut icon" href="../_static/ci-icon.ico"/>
  9. <link href='https://fonts.googleapis.com/css?family=Lato:400,700,400italic,700italic|Roboto+Slab:400,700|Inconsolata:400,700&subset=latin,cyrillic' rel='stylesheet' type='text/css'>
  10. <link rel="stylesheet" href="../_static/css/citheme.css" type="text/css" />
  11. <link rel="index" title="Index"
  12. href="../genindex.html"/>
  13. <link rel="search" title="Search" href="../search.html"/>
  14. <link rel="top" title="CodeIgniter 3.1.11 documentation" href="../index.html"/>
  15. <link rel="up" title="General Topics" href="index.html"/>
  16. <link rel="next" title="PHP Style Guide" href="styleguide.html"/>
  17. <link rel="prev" title="Alternate PHP Syntax for View Files" href="alternative_php.html"/>
  18. <script src="https://cdnjs.cloudflare.com/ajax/libs/modernizr/2.6.2/modernizr.min.js"></script>
  19. </head>
  20. <body class="wy-body-for-nav" role="document">
  21. <div id="nav">
  22. <div id="nav_inner">
  23. <div id="pulldown-menu" class="ciNav">
  24. <ul>
  25. <li class="toctree-l1"><a class="reference internal" href="welcome.html">Welcome to CodeIgniter</a></li>
  26. </ul>
  27. <ul>
  28. <li class="toctree-l1"><a class="reference internal" href="../installation/index.html">Installation Instructions</a><ul>
  29. <li class="toctree-l2"><a class="reference internal" href="../installation/downloads.html">Downloading CodeIgniter</a></li>
  30. <li class="toctree-l2"><a class="reference internal" href="../installation/index.html">Installation Instructions</a></li>
  31. <li class="toctree-l2"><a class="reference internal" href="../installation/upgrading.html">Upgrading From a Previous Version</a></li>
  32. <li class="toctree-l2"><a class="reference internal" href="../installation/troubleshooting.html">Troubleshooting</a></li>
  33. </ul>
  34. </li>
  35. </ul>
  36. <ul>
  37. <li class="toctree-l1"><a class="reference internal" href="../overview/index.html">CodeIgniter Overview</a><ul>
  38. <li class="toctree-l2"><a class="reference internal" href="../overview/getting_started.html">Getting Started</a></li>
  39. <li class="toctree-l2"><a class="reference internal" href="../overview/at_a_glance.html">CodeIgniter at a Glance</a></li>
  40. <li class="toctree-l2"><a class="reference internal" href="../overview/features.html">Supported Features</a></li>
  41. <li class="toctree-l2"><a class="reference internal" href="../overview/appflow.html">Application Flow Chart</a></li>
  42. <li class="toctree-l2"><a class="reference internal" href="../overview/mvc.html">Model-View-Controller</a></li>
  43. <li class="toctree-l2"><a class="reference internal" href="../overview/goals.html">Architectural Goals</a></li>
  44. </ul>
  45. </li>
  46. </ul>
  47. <ul>
  48. <li class="toctree-l1"><a class="reference internal" href="../tutorial/index.html">Tutorial</a><ul>
  49. <li class="toctree-l2"><a class="reference internal" href="../tutorial/static_pages.html">Static pages</a></li>
  50. <li class="toctree-l2"><a class="reference internal" href="../tutorial/news_section.html">News section</a></li>
  51. <li class="toctree-l2"><a class="reference internal" href="../tutorial/create_news_items.html">Create news items</a></li>
  52. <li class="toctree-l2"><a class="reference internal" href="../tutorial/conclusion.html">Conclusion</a></li>
  53. </ul>
  54. </li>
  55. </ul>
  56. <ul>
  57. <li class="toctree-l1"><a class="reference internal" href="../contributing/index.html">Contributing to CodeIgniter</a><ul>
  58. <li class="toctree-l2"><a class="reference internal" href="../documentation/index.html">Writing CodeIgniter Documentation</a></li>
  59. <li class="toctree-l2"><a class="reference internal" href="../DCO.html">Developer’s Certificate of Origin 1.1</a></li>
  60. </ul>
  61. </li>
  62. </ul>
  63. <ul class="current">
  64. <li class="toctree-l1 current"><a class="reference internal" href="index.html">General Topics</a><ul class="current">
  65. <li class="toctree-l2"><a class="reference internal" href="urls.html">CodeIgniter URLs</a></li>
  66. <li class="toctree-l2"><a class="reference internal" href="controllers.html">Controllers</a></li>
  67. <li class="toctree-l2"><a class="reference internal" href="reserved_names.html">Reserved Names</a></li>
  68. <li class="toctree-l2"><a class="reference internal" href="views.html">Views</a></li>
  69. <li class="toctree-l2"><a class="reference internal" href="models.html">Models</a></li>
  70. <li class="toctree-l2"><a class="reference internal" href="helpers.html">Helpers</a></li>
  71. <li class="toctree-l2"><a class="reference internal" href="libraries.html">Using CodeIgniter Libraries</a></li>
  72. <li class="toctree-l2"><a class="reference internal" href="creating_libraries.html">Creating Libraries</a></li>
  73. <li class="toctree-l2"><a class="reference internal" href="drivers.html">Using CodeIgniter Drivers</a></li>
  74. <li class="toctree-l2"><a class="reference internal" href="creating_drivers.html">Creating Drivers</a></li>
  75. <li class="toctree-l2"><a class="reference internal" href="core_classes.html">Creating Core System Classes</a></li>
  76. <li class="toctree-l2"><a class="reference internal" href="ancillary_classes.html">Creating Ancillary Classes</a></li>
  77. <li class="toctree-l2"><a class="reference internal" href="hooks.html">Hooks - Extending the Framework Core</a></li>
  78. <li class="toctree-l2"><a class="reference internal" href="autoloader.html">Auto-loading Resources</a></li>
  79. <li class="toctree-l2"><a class="reference internal" href="common_functions.html">Common Functions</a></li>
  80. <li class="toctree-l2"><a class="reference internal" href="compatibility_functions.html">Compatibility Functions</a></li>
  81. <li class="toctree-l2"><a class="reference internal" href="routing.html">URI Routing</a></li>
  82. <li class="toctree-l2"><a class="reference internal" href="errors.html">Error Handling</a></li>
  83. <li class="toctree-l2"><a class="reference internal" href="caching.html">Caching</a></li>
  84. <li class="toctree-l2"><a class="reference internal" href="profiling.html">Profiling Your Application</a></li>
  85. <li class="toctree-l2"><a class="reference internal" href="cli.html">Running via the CLI</a></li>
  86. <li class="toctree-l2"><a class="reference internal" href="managing_apps.html">Managing your Applications</a></li>
  87. <li class="toctree-l2"><a class="reference internal" href="environments.html">Handling Multiple Environments</a></li>
  88. <li class="toctree-l2"><a class="reference internal" href="alternative_php.html">Alternate PHP Syntax for View Files</a></li>
  89. <li class="toctree-l2 current"><a class="current reference internal" href="#">Security</a></li>
  90. <li class="toctree-l2"><a class="reference internal" href="styleguide.html">PHP Style Guide</a></li>
  91. </ul>
  92. </li>
  93. </ul>
  94. <ul>
  95. <li class="toctree-l1"><a class="reference internal" href="../libraries/index.html">Libraries</a><ul>
  96. <li class="toctree-l2"><a class="reference internal" href="../libraries/benchmark.html">Benchmarking Class</a></li>
  97. <li class="toctree-l2"><a class="reference internal" href="../libraries/caching.html">Caching Driver</a></li>
  98. <li class="toctree-l2"><a class="reference internal" href="../libraries/calendar.html">Calendaring Class</a></li>
  99. <li class="toctree-l2"><a class="reference internal" href="../libraries/cart.html">Shopping Cart Class</a></li>
  100. <li class="toctree-l2"><a class="reference internal" href="../libraries/config.html">Config Class</a></li>
  101. <li class="toctree-l2"><a class="reference internal" href="../libraries/email.html">Email Class</a></li>
  102. <li class="toctree-l2"><a class="reference internal" href="../libraries/encrypt.html">Encrypt Class</a></li>
  103. <li class="toctree-l2"><a class="reference internal" href="../libraries/encryption.html">Encryption Library</a></li>
  104. <li class="toctree-l2"><a class="reference internal" href="../libraries/file_uploading.html">File Uploading Class</a></li>
  105. <li class="toctree-l2"><a class="reference internal" href="../libraries/form_validation.html">Form Validation</a></li>
  106. <li class="toctree-l2"><a class="reference internal" href="../libraries/ftp.html">FTP Class</a></li>
  107. <li class="toctree-l2"><a class="reference internal" href="../libraries/image_lib.html">Image Manipulation Class</a></li>
  108. <li class="toctree-l2"><a class="reference internal" href="../libraries/input.html">Input Class</a></li>
  109. <li class="toctree-l2"><a class="reference internal" href="../libraries/javascript.html">Javascript Class</a></li>
  110. <li class="toctree-l2"><a class="reference internal" href="../libraries/language.html">Language Class</a></li>
  111. <li class="toctree-l2"><a class="reference internal" href="../libraries/loader.html">Loader Class</a></li>
  112. <li class="toctree-l2"><a class="reference internal" href="../libraries/migration.html">Migrations Class</a></li>
  113. <li class="toctree-l2"><a class="reference internal" href="../libraries/output.html">Output Class</a></li>
  114. <li class="toctree-l2"><a class="reference internal" href="../libraries/pagination.html">Pagination Class</a></li>
  115. <li class="toctree-l2"><a class="reference internal" href="../libraries/parser.html">Template Parser Class</a></li>
  116. <li class="toctree-l2"><a class="reference internal" href="../libraries/security.html">Security Class</a></li>
  117. <li class="toctree-l2"><a class="reference internal" href="../libraries/sessions.html">Session Library</a></li>
  118. <li class="toctree-l2"><a class="reference internal" href="../libraries/table.html">HTML Table Class</a></li>
  119. <li class="toctree-l2"><a class="reference internal" href="../libraries/trackback.html">Trackback Class</a></li>
  120. <li class="toctree-l2"><a class="reference internal" href="../libraries/typography.html">Typography Class</a></li>
  121. <li class="toctree-l2"><a class="reference internal" href="../libraries/unit_testing.html">Unit Testing Class</a></li>
  122. <li class="toctree-l2"><a class="reference internal" href="../libraries/uri.html">URI Class</a></li>
  123. <li class="toctree-l2"><a class="reference internal" href="../libraries/user_agent.html">User Agent Class</a></li>
  124. <li class="toctree-l2"><a class="reference internal" href="../libraries/xmlrpc.html">XML-RPC and XML-RPC Server Classes</a></li>
  125. <li class="toctree-l2"><a class="reference internal" href="../libraries/zip.html">Zip Encoding Class</a></li>
  126. </ul>
  127. </li>
  128. </ul>
  129. <ul>
  130. <li class="toctree-l1"><a class="reference internal" href="../database/index.html">Database Reference</a><ul>
  131. <li class="toctree-l2"><a class="reference internal" href="../database/examples.html">Quick Start: Usage Examples</a></li>
  132. <li class="toctree-l2"><a class="reference internal" href="../database/configuration.html">Database Configuration</a></li>
  133. <li class="toctree-l2"><a class="reference internal" href="../database/connecting.html">Connecting to a Database</a></li>
  134. <li class="toctree-l2"><a class="reference internal" href="../database/queries.html">Running Queries</a></li>
  135. <li class="toctree-l2"><a class="reference internal" href="../database/results.html">Generating Query Results</a></li>
  136. <li class="toctree-l2"><a class="reference internal" href="../database/helpers.html">Query Helper Functions</a></li>
  137. <li class="toctree-l2"><a class="reference internal" href="../database/query_builder.html">Query Builder Class</a></li>
  138. <li class="toctree-l2"><a class="reference internal" href="../database/transactions.html">Transactions</a></li>
  139. <li class="toctree-l2"><a class="reference internal" href="../database/metadata.html">Getting MetaData</a></li>
  140. <li class="toctree-l2"><a class="reference internal" href="../database/call_function.html">Custom Function Calls</a></li>
  141. <li class="toctree-l2"><a class="reference internal" href="../database/caching.html">Query Caching</a></li>
  142. <li class="toctree-l2"><a class="reference internal" href="../database/forge.html">Database Manipulation with Database Forge</a></li>
  143. <li class="toctree-l2"><a class="reference internal" href="../database/utilities.html">Database Utilities Class</a></li>
  144. <li class="toctree-l2"><a class="reference internal" href="../database/db_driver_reference.html">Database Driver Reference</a></li>
  145. </ul>
  146. </li>
  147. </ul>
  148. <ul>
  149. <li class="toctree-l1"><a class="reference internal" href="../helpers/index.html">Helpers</a><ul>
  150. <li class="toctree-l2"><a class="reference internal" href="../helpers/array_helper.html">Array Helper</a></li>
  151. <li class="toctree-l2"><a class="reference internal" href="../helpers/captcha_helper.html">CAPTCHA Helper</a></li>
  152. <li class="toctree-l2"><a class="reference internal" href="../helpers/cookie_helper.html">Cookie Helper</a></li>
  153. <li class="toctree-l2"><a class="reference internal" href="../helpers/date_helper.html">Date Helper</a></li>
  154. <li class="toctree-l2"><a class="reference internal" href="../helpers/directory_helper.html">Directory Helper</a></li>
  155. <li class="toctree-l2"><a class="reference internal" href="../helpers/download_helper.html">Download Helper</a></li>
  156. <li class="toctree-l2"><a class="reference internal" href="../helpers/email_helper.html">Email Helper</a></li>
  157. <li class="toctree-l2"><a class="reference internal" href="../helpers/file_helper.html">File Helper</a></li>
  158. <li class="toctree-l2"><a class="reference internal" href="../helpers/form_helper.html">Form Helper</a></li>
  159. <li class="toctree-l2"><a class="reference internal" href="../helpers/html_helper.html">HTML Helper</a></li>
  160. <li class="toctree-l2"><a class="reference internal" href="../helpers/inflector_helper.html">Inflector Helper</a></li>
  161. <li class="toctree-l2"><a class="reference internal" href="../helpers/language_helper.html">Language Helper</a></li>
  162. <li class="toctree-l2"><a class="reference internal" href="../helpers/number_helper.html">Number Helper</a></li>
  163. <li class="toctree-l2"><a class="reference internal" href="../helpers/path_helper.html">Path Helper</a></li>
  164. <li class="toctree-l2"><a class="reference internal" href="../helpers/security_helper.html">Security Helper</a></li>
  165. <li class="toctree-l2"><a class="reference internal" href="../helpers/smiley_helper.html">Smiley Helper</a></li>
  166. <li class="toctree-l2"><a class="reference internal" href="../helpers/string_helper.html">String Helper</a></li>
  167. <li class="toctree-l2"><a class="reference internal" href="../helpers/text_helper.html">Text Helper</a></li>
  168. <li class="toctree-l2"><a class="reference internal" href="../helpers/typography_helper.html">Typography Helper</a></li>
  169. <li class="toctree-l2"><a class="reference internal" href="../helpers/url_helper.html">URL Helper</a></li>
  170. <li class="toctree-l2"><a class="reference internal" href="../helpers/xml_helper.html">XML Helper</a></li>
  171. </ul>
  172. </li>
  173. </ul>
  174. </div>
  175. </div>
  176. </div>
  177. <div id="nav2">
  178. <a href="#" id="openToc">
  179. <img src="" title="Toggle Table of Contents" alt="Toggle Table of Contents" />
  180. </a>
  181. </div>
  182. <div class="wy-grid-for-nav">
  183. <nav data-toggle="wy-nav-shift" class="wy-nav-side">
  184. <div class="wy-side-nav-search">
  185. <a href="../index.html" class="fa fa-home"> CodeIgniter</a>
  186. <div role="search">
  187. <form id="rtd-search-form" class="wy-form" action="../search.html" method="get">
  188. <input type="text" name="q" placeholder="Search docs" />
  189. <input type="hidden" name="check_keywords" value="yes" />
  190. <input type="hidden" name="area" value="default" />
  191. </form>
  192. </div>
  193. </div>
  194. <div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="main navigation">
  195. <ul>
  196. <li class="toctree-l1"><a class="reference internal" href="welcome.html">Welcome to CodeIgniter</a></li>
  197. </ul>
  198. <ul>
  199. <li class="toctree-l1"><a class="reference internal" href="../installation/index.html">Installation Instructions</a><ul>
  200. <li class="toctree-l2"><a class="reference internal" href="../installation/downloads.html">Downloading CodeIgniter</a></li>
  201. <li class="toctree-l2"><a class="reference internal" href="../installation/index.html">Installation Instructions</a></li>
  202. <li class="toctree-l2"><a class="reference internal" href="../installation/upgrading.html">Upgrading From a Previous Version</a></li>
  203. <li class="toctree-l2"><a class="reference internal" href="../installation/troubleshooting.html">Troubleshooting</a></li>
  204. </ul>
  205. </li>
  206. </ul>
  207. <ul>
  208. <li class="toctree-l1"><a class="reference internal" href="../overview/index.html">CodeIgniter Overview</a><ul>
  209. <li class="toctree-l2"><a class="reference internal" href="../overview/getting_started.html">Getting Started</a></li>
  210. <li class="toctree-l2"><a class="reference internal" href="../overview/at_a_glance.html">CodeIgniter at a Glance</a></li>
  211. <li class="toctree-l2"><a class="reference internal" href="../overview/features.html">Supported Features</a></li>
  212. <li class="toctree-l2"><a class="reference internal" href="../overview/appflow.html">Application Flow Chart</a></li>
  213. <li class="toctree-l2"><a class="reference internal" href="../overview/mvc.html">Model-View-Controller</a></li>
  214. <li class="toctree-l2"><a class="reference internal" href="../overview/goals.html">Architectural Goals</a></li>
  215. </ul>
  216. </li>
  217. </ul>
  218. <ul>
  219. <li class="toctree-l1"><a class="reference internal" href="../tutorial/index.html">Tutorial</a><ul>
  220. <li class="toctree-l2"><a class="reference internal" href="../tutorial/static_pages.html">Static pages</a></li>
  221. <li class="toctree-l2"><a class="reference internal" href="../tutorial/news_section.html">News section</a></li>
  222. <li class="toctree-l2"><a class="reference internal" href="../tutorial/create_news_items.html">Create news items</a></li>
  223. <li class="toctree-l2"><a class="reference internal" href="../tutorial/conclusion.html">Conclusion</a></li>
  224. </ul>
  225. </li>
  226. </ul>
  227. <ul>
  228. <li class="toctree-l1"><a class="reference internal" href="../contributing/index.html">Contributing to CodeIgniter</a><ul>
  229. <li class="toctree-l2"><a class="reference internal" href="../documentation/index.html">Writing CodeIgniter Documentation</a></li>
  230. <li class="toctree-l2"><a class="reference internal" href="../DCO.html">Developer’s Certificate of Origin 1.1</a></li>
  231. </ul>
  232. </li>
  233. </ul>
  234. <ul class="current">
  235. <li class="toctree-l1 current"><a class="reference internal" href="index.html">General Topics</a><ul class="current">
  236. <li class="toctree-l2"><a class="reference internal" href="urls.html">CodeIgniter URLs</a></li>
  237. <li class="toctree-l2"><a class="reference internal" href="controllers.html">Controllers</a></li>
  238. <li class="toctree-l2"><a class="reference internal" href="reserved_names.html">Reserved Names</a></li>
  239. <li class="toctree-l2"><a class="reference internal" href="views.html">Views</a></li>
  240. <li class="toctree-l2"><a class="reference internal" href="models.html">Models</a></li>
  241. <li class="toctree-l2"><a class="reference internal" href="helpers.html">Helpers</a></li>
  242. <li class="toctree-l2"><a class="reference internal" href="libraries.html">Using CodeIgniter Libraries</a></li>
  243. <li class="toctree-l2"><a class="reference internal" href="creating_libraries.html">Creating Libraries</a></li>
  244. <li class="toctree-l2"><a class="reference internal" href="drivers.html">Using CodeIgniter Drivers</a></li>
  245. <li class="toctree-l2"><a class="reference internal" href="creating_drivers.html">Creating Drivers</a></li>
  246. <li class="toctree-l2"><a class="reference internal" href="core_classes.html">Creating Core System Classes</a></li>
  247. <li class="toctree-l2"><a class="reference internal" href="ancillary_classes.html">Creating Ancillary Classes</a></li>
  248. <li class="toctree-l2"><a class="reference internal" href="hooks.html">Hooks - Extending the Framework Core</a></li>
  249. <li class="toctree-l2"><a class="reference internal" href="autoloader.html">Auto-loading Resources</a></li>
  250. <li class="toctree-l2"><a class="reference internal" href="common_functions.html">Common Functions</a></li>
  251. <li class="toctree-l2"><a class="reference internal" href="compatibility_functions.html">Compatibility Functions</a></li>
  252. <li class="toctree-l2"><a class="reference internal" href="routing.html">URI Routing</a></li>
  253. <li class="toctree-l2"><a class="reference internal" href="errors.html">Error Handling</a></li>
  254. <li class="toctree-l2"><a class="reference internal" href="caching.html">Caching</a></li>
  255. <li class="toctree-l2"><a class="reference internal" href="profiling.html">Profiling Your Application</a></li>
  256. <li class="toctree-l2"><a class="reference internal" href="cli.html">Running via the CLI</a></li>
  257. <li class="toctree-l2"><a class="reference internal" href="managing_apps.html">Managing your Applications</a></li>
  258. <li class="toctree-l2"><a class="reference internal" href="environments.html">Handling Multiple Environments</a></li>
  259. <li class="toctree-l2"><a class="reference internal" href="alternative_php.html">Alternate PHP Syntax for View Files</a></li>
  260. <li class="toctree-l2 current"><a class="current reference internal" href="#">Security</a></li>
  261. <li class="toctree-l2"><a class="reference internal" href="styleguide.html">PHP Style Guide</a></li>
  262. </ul>
  263. </li>
  264. </ul>
  265. <ul>
  266. <li class="toctree-l1"><a class="reference internal" href="../libraries/index.html">Libraries</a><ul>
  267. <li class="toctree-l2"><a class="reference internal" href="../libraries/benchmark.html">Benchmarking Class</a></li>
  268. <li class="toctree-l2"><a class="reference internal" href="../libraries/caching.html">Caching Driver</a></li>
  269. <li class="toctree-l2"><a class="reference internal" href="../libraries/calendar.html">Calendaring Class</a></li>
  270. <li class="toctree-l2"><a class="reference internal" href="../libraries/cart.html">Shopping Cart Class</a></li>
  271. <li class="toctree-l2"><a class="reference internal" href="../libraries/config.html">Config Class</a></li>
  272. <li class="toctree-l2"><a class="reference internal" href="../libraries/email.html">Email Class</a></li>
  273. <li class="toctree-l2"><a class="reference internal" href="../libraries/encrypt.html">Encrypt Class</a></li>
  274. <li class="toctree-l2"><a class="reference internal" href="../libraries/encryption.html">Encryption Library</a></li>
  275. <li class="toctree-l2"><a class="reference internal" href="../libraries/file_uploading.html">File Uploading Class</a></li>
  276. <li class="toctree-l2"><a class="reference internal" href="../libraries/form_validation.html">Form Validation</a></li>
  277. <li class="toctree-l2"><a class="reference internal" href="../libraries/ftp.html">FTP Class</a></li>
  278. <li class="toctree-l2"><a class="reference internal" href="../libraries/image_lib.html">Image Manipulation Class</a></li>
  279. <li class="toctree-l2"><a class="reference internal" href="../libraries/input.html">Input Class</a></li>
  280. <li class="toctree-l2"><a class="reference internal" href="../libraries/javascript.html">Javascript Class</a></li>
  281. <li class="toctree-l2"><a class="reference internal" href="../libraries/language.html">Language Class</a></li>
  282. <li class="toctree-l2"><a class="reference internal" href="../libraries/loader.html">Loader Class</a></li>
  283. <li class="toctree-l2"><a class="reference internal" href="../libraries/migration.html">Migrations Class</a></li>
  284. <li class="toctree-l2"><a class="reference internal" href="../libraries/output.html">Output Class</a></li>
  285. <li class="toctree-l2"><a class="reference internal" href="../libraries/pagination.html">Pagination Class</a></li>
  286. <li class="toctree-l2"><a class="reference internal" href="../libraries/parser.html">Template Parser Class</a></li>
  287. <li class="toctree-l2"><a class="reference internal" href="../libraries/security.html">Security Class</a></li>
  288. <li class="toctree-l2"><a class="reference internal" href="../libraries/sessions.html">Session Library</a></li>
  289. <li class="toctree-l2"><a class="reference internal" href="../libraries/table.html">HTML Table Class</a></li>
  290. <li class="toctree-l2"><a class="reference internal" href="../libraries/trackback.html">Trackback Class</a></li>
  291. <li class="toctree-l2"><a class="reference internal" href="../libraries/typography.html">Typography Class</a></li>
  292. <li class="toctree-l2"><a class="reference internal" href="../libraries/unit_testing.html">Unit Testing Class</a></li>
  293. <li class="toctree-l2"><a class="reference internal" href="../libraries/uri.html">URI Class</a></li>
  294. <li class="toctree-l2"><a class="reference internal" href="../libraries/user_agent.html">User Agent Class</a></li>
  295. <li class="toctree-l2"><a class="reference internal" href="../libraries/xmlrpc.html">XML-RPC and XML-RPC Server Classes</a></li>
  296. <li class="toctree-l2"><a class="reference internal" href="../libraries/zip.html">Zip Encoding Class</a></li>
  297. </ul>
  298. </li>
  299. </ul>
  300. <ul>
  301. <li class="toctree-l1"><a class="reference internal" href="../database/index.html">Database Reference</a><ul>
  302. <li class="toctree-l2"><a class="reference internal" href="../database/examples.html">Quick Start: Usage Examples</a></li>
  303. <li class="toctree-l2"><a class="reference internal" href="../database/configuration.html">Database Configuration</a></li>
  304. <li class="toctree-l2"><a class="reference internal" href="../database/connecting.html">Connecting to a Database</a></li>
  305. <li class="toctree-l2"><a class="reference internal" href="../database/queries.html">Running Queries</a></li>
  306. <li class="toctree-l2"><a class="reference internal" href="../database/results.html">Generating Query Results</a></li>
  307. <li class="toctree-l2"><a class="reference internal" href="../database/helpers.html">Query Helper Functions</a></li>
  308. <li class="toctree-l2"><a class="reference internal" href="../database/query_builder.html">Query Builder Class</a></li>
  309. <li class="toctree-l2"><a class="reference internal" href="../database/transactions.html">Transactions</a></li>
  310. <li class="toctree-l2"><a class="reference internal" href="../database/metadata.html">Getting MetaData</a></li>
  311. <li class="toctree-l2"><a class="reference internal" href="../database/call_function.html">Custom Function Calls</a></li>
  312. <li class="toctree-l2"><a class="reference internal" href="../database/caching.html">Query Caching</a></li>
  313. <li class="toctree-l2"><a class="reference internal" href="../database/forge.html">Database Manipulation with Database Forge</a></li>
  314. <li class="toctree-l2"><a class="reference internal" href="../database/utilities.html">Database Utilities Class</a></li>
  315. <li class="toctree-l2"><a class="reference internal" href="../database/db_driver_reference.html">Database Driver Reference</a></li>
  316. </ul>
  317. </li>
  318. </ul>
  319. <ul>
  320. <li class="toctree-l1"><a class="reference internal" href="../helpers/index.html">Helpers</a><ul>
  321. <li class="toctree-l2"><a class="reference internal" href="../helpers/array_helper.html">Array Helper</a></li>
  322. <li class="toctree-l2"><a class="reference internal" href="../helpers/captcha_helper.html">CAPTCHA Helper</a></li>
  323. <li class="toctree-l2"><a class="reference internal" href="../helpers/cookie_helper.html">Cookie Helper</a></li>
  324. <li class="toctree-l2"><a class="reference internal" href="../helpers/date_helper.html">Date Helper</a></li>
  325. <li class="toctree-l2"><a class="reference internal" href="../helpers/directory_helper.html">Directory Helper</a></li>
  326. <li class="toctree-l2"><a class="reference internal" href="../helpers/download_helper.html">Download Helper</a></li>
  327. <li class="toctree-l2"><a class="reference internal" href="../helpers/email_helper.html">Email Helper</a></li>
  328. <li class="toctree-l2"><a class="reference internal" href="../helpers/file_helper.html">File Helper</a></li>
  329. <li class="toctree-l2"><a class="reference internal" href="../helpers/form_helper.html">Form Helper</a></li>
  330. <li class="toctree-l2"><a class="reference internal" href="../helpers/html_helper.html">HTML Helper</a></li>
  331. <li class="toctree-l2"><a class="reference internal" href="../helpers/inflector_helper.html">Inflector Helper</a></li>
  332. <li class="toctree-l2"><a class="reference internal" href="../helpers/language_helper.html">Language Helper</a></li>
  333. <li class="toctree-l2"><a class="reference internal" href="../helpers/number_helper.html">Number Helper</a></li>
  334. <li class="toctree-l2"><a class="reference internal" href="../helpers/path_helper.html">Path Helper</a></li>
  335. <li class="toctree-l2"><a class="reference internal" href="../helpers/security_helper.html">Security Helper</a></li>
  336. <li class="toctree-l2"><a class="reference internal" href="../helpers/smiley_helper.html">Smiley Helper</a></li>
  337. <li class="toctree-l2"><a class="reference internal" href="../helpers/string_helper.html">String Helper</a></li>
  338. <li class="toctree-l2"><a class="reference internal" href="../helpers/text_helper.html">Text Helper</a></li>
  339. <li class="toctree-l2"><a class="reference internal" href="../helpers/typography_helper.html">Typography Helper</a></li>
  340. <li class="toctree-l2"><a class="reference internal" href="../helpers/url_helper.html">URL Helper</a></li>
  341. <li class="toctree-l2"><a class="reference internal" href="../helpers/xml_helper.html">XML Helper</a></li>
  342. </ul>
  343. </li>
  344. </ul>
  345. </div>
  346. &nbsp;
  347. </nav>
  348. <section data-toggle="wy-nav-shift" class="wy-nav-content-wrap">
  349. <nav class="wy-nav-top" role="navigation" aria-label="top navigation">
  350. <i data-toggle="wy-nav-top" class="fa fa-bars"></i>
  351. <a href="../index.html">CodeIgniter</a>
  352. </nav>
  353. <div class="wy-nav-content">
  354. <div class="rst-content">
  355. <div role="navigation" aria-label="breadcrumbs navigation">
  356. <ul class="wy-breadcrumbs">
  357. <li><a href="../index.html">Docs</a> &raquo;</li>
  358. <li><a href="index.html">General Topics</a> &raquo;</li>
  359. <li>Security</li>
  360. <li class="wy-breadcrumbs-aside">
  361. </li>
  362. <div style="float:right;margin-left:5px;" id="closeMe">
  363. <img title="Classic Layout" alt="classic layout" src="" />
  364. </div>
  365. </ul>
  366. <hr/>
  367. </div>
  368. <div role="main" class="document">
  369. <div class="section" id="security">
  370. <h1>Security<a class="headerlink" href="#security" title="Permalink to this headline">¶</a></h1>
  371. <p>This page describes some “best practices” regarding web security, and
  372. details CodeIgniter’s internal security features.</p>
  373. <div class="admonition note">
  374. <p class="first admonition-title">Note</p>
  375. <p class="last">If you came here looking for a security contact, please refer to
  376. our <cite>Contribution Guide &lt;../contributing/index&gt;</cite>.</p>
  377. </div>
  378. <div class="section" id="uri-security">
  379. <h2>URI Security<a class="headerlink" href="#uri-security" title="Permalink to this headline">¶</a></h2>
  380. <p>CodeIgniter is fairly restrictive regarding which characters it allows
  381. in your URI strings in order to help minimize the possibility that
  382. malicious data can be passed to your application. URIs may only contain
  383. the following:</p>
  384. <ul class="simple">
  385. <li>Alpha-numeric text (latin characters only)</li>
  386. <li>Tilde: ~</li>
  387. <li>Percent sign: %</li>
  388. <li>Period: .</li>
  389. <li>Colon: :</li>
  390. <li>Underscore: _</li>
  391. <li>Dash: -</li>
  392. <li>Space</li>
  393. </ul>
  394. </div>
  395. <div class="section" id="register-globals">
  396. <h2>Register_globals<a class="headerlink" href="#register-globals" title="Permalink to this headline">¶</a></h2>
  397. <p>During system initialization all global variables that are found to exist
  398. in the <code class="docutils literal"><span class="pre">$_GET</span></code>, <code class="docutils literal"><span class="pre">$_POST</span></code>, <code class="docutils literal"><span class="pre">$_REQUEST</span></code> and <code class="docutils literal"><span class="pre">$_COOKIE</span></code> are unset.</p>
  399. <p>The unsetting routine is effectively the same as <em>register_globals = off</em>.</p>
  400. </div>
  401. <div class="section" id="display-errors">
  402. <h2>display_errors<a class="headerlink" href="#display-errors" title="Permalink to this headline">¶</a></h2>
  403. <p>In production environments, it is typically desirable to “disable” PHP’s
  404. error reporting by setting the internal <em>display_errors</em> flag to a value
  405. of 0. This disables native PHP errors from being rendered as output,
  406. which may potentially contain sensitive information.</p>
  407. <p>Setting CodeIgniter’s <strong>ENVIRONMENT</strong> constant in index.php to a value of
  408. <strong>‘production’</strong> will turn off these errors. In development mode, it is
  409. recommended that a value of ‘development’ is used. More information
  410. about differentiating between environments can be found on the
  411. <a class="reference internal" href="environments.html"><span class="doc">Handling Environments</span></a> page.</p>
  412. </div>
  413. <div class="section" id="magic-quotes-runtime">
  414. <h2>magic_quotes_runtime<a class="headerlink" href="#magic-quotes-runtime" title="Permalink to this headline">¶</a></h2>
  415. <p>The <em>magic_quotes_runtime</em> directive is turned off during system
  416. initialization so that you don’t have to remove slashes when retrieving
  417. data from your database.</p>
  418. <div class="section" id="best-practices">
  419. <h3>Best Practices<a class="headerlink" href="#best-practices" title="Permalink to this headline">¶</a></h3>
  420. <p>Before accepting any data into your application, whether it be POST data
  421. from a form submission, COOKIE data, URI data, XML-RPC data, or even
  422. data from the SERVER array, you are encouraged to practice this three
  423. step approach:</p>
  424. <ol class="arabic simple">
  425. <li>Validate the data to ensure it conforms to the correct type, length,
  426. size, etc.</li>
  427. <li>Filter the data as if it were tainted.</li>
  428. <li>Escape the data before submitting it into your database or outputting
  429. it to a browser.</li>
  430. </ol>
  431. <p>CodeIgniter provides the following functions and tips to assist you
  432. in this process:</p>
  433. </div>
  434. </div>
  435. <div class="section" id="xss-filtering">
  436. <h2>XSS Filtering<a class="headerlink" href="#xss-filtering" title="Permalink to this headline">¶</a></h2>
  437. <p>CodeIgniter comes with a Cross Site Scripting filter. This filter
  438. looks for commonly used techniques to embed malicious JavaScript into
  439. your data, or other types of code that attempt to hijack cookies or
  440. do other malicious things. The XSS Filter is described
  441. <a class="reference internal" href="../libraries/security.html"><span class="doc">here</span></a>.</p>
  442. <div class="admonition note">
  443. <p class="first admonition-title">Note</p>
  444. <p class="last">XSS filtering should <em>only be performed on output</em>. Filtering
  445. input data may modify the data in undesirable ways, including
  446. stripping special characters from passwords, which reduces
  447. security instead of improving it.</p>
  448. </div>
  449. </div>
  450. <div class="section" id="csrf-protection">
  451. <h2>CSRF protection<a class="headerlink" href="#csrf-protection" title="Permalink to this headline">¶</a></h2>
  452. <p>CSRF stands for Cross-Site Request Forgery, which is the process of an
  453. attacker tricking their victim into unknowingly submitting a request.</p>
  454. <p>CodeIgniter provides CSRF protection out of the box, which will get
  455. automatically triggered for every non-GET HTTP request, but also needs
  456. you to create your submit forms in a certain way. This is explained in
  457. the <a class="reference internal" href="../libraries/security.html"><span class="doc">Security Library</span></a> documentation.</p>
  458. </div>
  459. <div class="section" id="password-handling">
  460. <h2>Password handling<a class="headerlink" href="#password-handling" title="Permalink to this headline">¶</a></h2>
  461. <p>It is <em>critical</em> that you handle passwords in your application properly.</p>
  462. <p>Unfortunately, many developers don’t know how to do that, and the web is
  463. full of outdated or otherwise wrongful advices, which doesn’t help.</p>
  464. <p>We would like to give you a list of combined do’s and don’ts to help you
  465. with that. Please read below.</p>
  466. <ul>
  467. <li><p class="first">DO NOT store passwords in plain-text format.</p>
  468. <p>Always <strong>hash</strong> your passwords.</p>
  469. </li>
  470. <li><p class="first">DO NOT use Base64 or similar encoding for storing passwords.</p>
  471. <p>This is as good as storing them in plain-text. Really. Do <strong>hashing</strong>,
  472. not <em>encoding</em>.</p>
  473. <p>Encoding, and encryption too, are two-way processes. Passwords are
  474. secrets that must only be known to their owner, and thus must work
  475. only in one direction. Hashing does that - there’s <em>no</em> un-hashing or
  476. de-hashing, but there is decoding and decryption.</p>
  477. </li>
  478. <li><p class="first">DO NOT use weak or broken hashing algorithms like MD5 or SHA1.</p>
  479. <p>These algorithms are old, proven to be flawed, and not designed for
  480. password hashing in the first place.</p>
  481. <p>Also, DON’T invent your own algorithms.</p>
  482. <p>Only use strong password hashing algorithms like BCrypt, which is used
  483. in PHP’s own <a class="reference external" href="http://php.net/password">Password Hashing</a> functions.</p>
  484. <p>Please use them, even if you’re not running PHP 5.5+, CodeIgniter
  485. provides them for you.</p>
  486. </li>
  487. <li><p class="first">DO NOT ever display or send a password in plain-text format!</p>
  488. <p>Even to the password’s owner, if you need a “Forgotten password”
  489. feature, just randomly generate a new, one-time (this is also important)
  490. password and send that instead.</p>
  491. </li>
  492. <li><p class="first">DO NOT put unnecessary limits on your users’ passwords.</p>
  493. <p>If you’re using a hashing algorithm other than BCrypt (which has a limit
  494. of 72 characters), you should set a relatively high limit on password
  495. lengths in order to mitigate DoS attacks - say, 1024 characters.</p>
  496. <p>Other than that however, there’s no point in forcing a rule that a
  497. password can only be up to a number of characters, or that it can’t
  498. contain a certain set of special characters.</p>
  499. <p>Not only does this <strong>reduce</strong> security instead of improving it, but
  500. there’s literally no reason to do it. No technical limitations and
  501. no (practical) storage constraints apply once you’ve hashed them, none!</p>
  502. </li>
  503. </ul>
  504. </div>
  505. <div class="section" id="validate-input-data">
  506. <h2>Validate input data<a class="headerlink" href="#validate-input-data" title="Permalink to this headline">¶</a></h2>
  507. <p>CodeIgniter has a <a class="reference internal" href="../libraries/form_validation.html"><span class="doc">Form Validation Library</span></a> that assists you in
  508. validating, filtering, and prepping your data.</p>
  509. <p>Even if that doesn’t work for your use case however, be sure to always
  510. validate and sanitize all input data. For example, if you expect a numeric
  511. string for an input variable, you can check for that with <code class="docutils literal"><span class="pre">is_numeric()</span></code>
  512. or <code class="docutils literal"><span class="pre">ctype_digit()</span></code>. Always try to narrow down your checks to a certain
  513. pattern.</p>
  514. <p>Have it in mind that this includes not only <code class="docutils literal"><span class="pre">$_POST</span></code> and <code class="docutils literal"><span class="pre">$_GET</span></code>
  515. variables, but also cookies, the user-agent string and basically
  516. <em>all data that is not created directly by your own code</em>.</p>
  517. </div>
  518. <div class="section" id="escape-all-data-before-database-insertion">
  519. <h2>Escape all data before database insertion<a class="headerlink" href="#escape-all-data-before-database-insertion" title="Permalink to this headline">¶</a></h2>
  520. <p>Never insert information into your database without escaping it.
  521. Please see the section that discusses <a class="reference internal" href="../database/queries.html"><span class="doc">database queries</span></a> for more information.</p>
  522. </div>
  523. <div class="section" id="hide-your-files">
  524. <h2>Hide your files<a class="headerlink" href="#hide-your-files" title="Permalink to this headline">¶</a></h2>
  525. <p>Another good security practice is to only leave your <em>index.php</em>
  526. and “assets” (e.g. .js, css and image files) under your server’s
  527. <em>webroot</em> directory (most commonly named “htdocs/”). These are
  528. the only files that you would need to be accessible from the web.</p>
  529. <p>Allowing your visitors to see anything else would potentially
  530. allow them to access sensitive data, execute scripts, etc.</p>
  531. <p>If you’re not allowed to do that, you can try using a .htaccess
  532. file to restrict access to those resources.</p>
  533. <p>CodeIgniter will have an index.html file in all of its
  534. directories in an attempt to hide some of this data, but have
  535. it in mind that this is not enough to prevent a serious
  536. attacker.</p>
  537. </div>
  538. </div>
  539. </div>
  540. <footer>
  541. <div class="rst-footer-buttons" role="navigation" aria-label="footer navigation">
  542. <a href="styleguide.html" class="btn btn-neutral float-right" title="PHP Style Guide">Next <span class="fa fa-arrow-circle-right"></span></a>
  543. <a href="alternative_php.html" class="btn btn-neutral" title="Alternate PHP Syntax for View Files"><span class="fa fa-arrow-circle-left"></span> Previous</a>
  544. </div>
  545. <hr/>
  546. <div role="contentinfo">
  547. <p>
  548. &copy; Copyright 2014 - 2019, British Columbia Institute of Technology.
  549. Last updated on Sep 19, 2019.
  550. </p>
  551. </div>
  552. Built with <a href="http://sphinx-doc.org/">Sphinx</a> using a <a href="https://github.com/snide/sphinx_rtd_theme">theme</a> provided by <a href="https://readthedocs.org">Read the Docs</a>.
  553. </footer>
  554. </div>
  555. </div>
  556. </section>
  557. </div>
  558. <script type="text/javascript">
  559. var DOCUMENTATION_OPTIONS = {
  560. URL_ROOT:'../',
  561. VERSION:'3.1.11',
  562. COLLAPSE_INDEX:false,
  563. FILE_SUFFIX:'.html',
  564. HAS_SOURCE: false
  565. };
  566. </script>
  567. <script type="text/javascript" src="../_static/jquery.js"></script>
  568. <script type="text/javascript" src="../_static/underscore.js"></script>
  569. <script type="text/javascript" src="../_static/doctools.js"></script>
  570. <script type="text/javascript" src="../_static/js/theme.js"></script>
  571. <script type="text/javascript">
  572. jQuery(function () {
  573. SphinxRtdTheme.StickyNav.enable();
  574. });
  575. </script>
  576. </body>
  577. </html>