Ask HN: please review my tool for rewrite rule testing
martinmelin.se
martinmelin.se
REQUEST_FILENAME: I tried blank, "year/month/day/post-name" and "/year/month/day/post-name".
URL: year/month/day/post-name (to give hostname/year/month/day/post-name).
Rewrite rules copied from the WP link above:
# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress
I got one no match and two rules skipped.EDIT: You have an XSS vulnerability in the URL field. Use the first test from this list: http://ha.ckers.org/xss.html .
RewriteRule . /index.php<script>alert(document.location)</script> [L]
and submitting a URL.Trivial nit: backslashes are doubled when rules are restored from the session.
I will definitely use this next time I have to hack 'n slash some rewrite rules though!
I'm missing one important feature though: there is no way to test different host names. I use rewrite rules that check country specific TLDs on the domain name and also rules that check if the domain starts with "m." for mobile specific access by matching against %{HTTP_HOST}. This would also allow one to check if the URL is using an IP address instead of a domain name. This would seem a common need, right?
Another suggestion: why not just use localStorage instead of a $_SESSION?