Encrypted URLs
One misconception that we periodically hear is Fusebox’s dependence on URL variables. “Fusebox can’t be secured,” some misinformed developers say. The truth of the matter is that Fusebox might be considered more secure than traditional ColdFusion applications. Sure, we rely on one more variable in the URL string (?fuseaction=circuit.fuseaction), but because of the security code that goes in Application.cfm mentioned in Chapter 3, “The Fusebox Framework,” our applications are less open to malicious users.
Nonetheless, some people are concerned about URL hacking, and Fusebox is just as susceptible to it as any dynamic application that relies on variables, whether variables are passed in a form or on the URL string. Take, for example, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access