summaryrefslogtreecommitdiff
path: root/index.php
diff options
context:
space:
mode:
Diffstat (limited to 'index.php')
-rw-r--r--index.php6
1 files changed, 5 insertions, 1 deletions
diff --git a/index.php b/index.php
index 9501e2275..6079d1f2c 100644
--- a/index.php
+++ b/index.php
@@ -272,7 +272,11 @@ function main()
return;
}
- $args = array_merge($args, $_REQUEST);
+ // Note the order here: arguments from the URL mapper will
+ // override request params that have been sent. This ensures
+ // that for instance an action parameter can't be overridden
+ // with an arbitrary action class.
+ $args = array_merge($_REQUEST, $args);
Event::handle('ArgsInitialize', array(&$args));