It would probably be sufficient to just add a very brief mention to the docs of 1.11, the two things that confused the heck out of me -If we were going to leave this behavior in for some time, then I think it'd be appropriate to at least mention it (maybe I'll just mention it anyway, without a comprehensive explanation 1) The accept/reject filters are applied twice, once to the URL filename before retrieval and once to the local filename after retrieval, and 2) A query string is not considered to be part of the URL filename. You can probably imagine my confusion when I saw [EMAIL PROTECTED] being saved. I then tried to prevent that link from being traversed with a match on part of the query string, and I'd see that file disappear, only to later realize it was traversed. I had no idea that the query string was not being considered during the acc/rej match, nor that the process was performed twice. I look forward to 1.12. |
- Re: Accept and Reject - particularly for PHP and CGI sites Todd Pattist
- Re: Accept and Reject - particularly for PHP and CGI sites Todd Pattist
- Re: Accept and Reject - particularly for PHP and CGI sites Todd Pattist
- Re: Accept and Reject - particularly for PHP and CGI sites Todd Pattist