Funnelback logo

Documentation

CATEGORY

Form security.allow query transforms (collection.cfg)

Description

This collection.cfg option enables query transformations. Setting it to "enabled" will allow query transforms, setting it to any other value will deny them. This setting should almost always be enabled.

Caveats

  • Enabling query transforms will enable users who can edit your collections query_transform.cfg to run arbitrary code on your server, with a permission level equal to that of the Funnelback web server. Users who can edit this file will almost always be trusted to run code on your server, so this should very rarely be a problem.

Default value

form_security.allow_query_transforms=enabled

Examples

Query transforms can be disabled.

form_security.allow_query_transforms=disabled

See also

top ⇑