07-31-2022, 09:15 PM
ServerController.BlockedDocExtensions property by default contains .php extension. The reason is that 99.9999999999% of all attack/exploit kits available out there - that are used by someone trying to gain access to your application and/or server - uses several requests all targeting some .php file. IntraWeb by default refuses to process those requests.
Use the ServerController.OnConfig event to remove .php extension from BlockedDocExtensions:
procedure TIWServerController.IWServerControllerBaseConfig(Sender: TObject);
begin
BlockedDocExtensions.Remove('.php');
end;
Use the ServerController.OnConfig event to remove .php extension from BlockedDocExtensions:
procedure TIWServerController.IWServerControllerBaseConfig(Sender: TObject);
begin
BlockedDocExtensions.Remove('.php');
end;