Published by Mijingo

movie icon image

EE Insider Blog

Spend your time learning and developing sites with ExpressionEngine and we'll use this blog to keep you informed of all the news related to ExpressionEngine and CodeIgniter.

» Read more in the Archives.

» Have a tip? Send us your EE news.

Learn ExpressionEngine Today

Over a series of 8 videos, watch and learn as Ryan builds an entire ExpressionEngine website from beginning to end. Get started now.

Protect Member Pages

It’s well known that if you don’t change your member profile trigger word from the default of “member,” that anyone can browse to your site and see a list of members.

This recently came up again in a tweet from Ryan Masuga and what followed were some good suggestions on what to do make the issue of inadvertently exposing your member list go away.

(My favorite is AJ Penniga’s highly technical solution to the problem.)

Read a full list of the suggestions

Posted on Dec 01, 2011 by Ryan Irelan

Filed Under: Development Tools

Fred Carlsen11:00 on 12.01.2011

I think you should include some of the tips here, because those Twitter links are most likely going to die/become unaccessible.

I think the best solution is Rob’s suggestion of setting the trigger to %, which causes a 400 Bad Request reply. It makes the member page totally unaccessible.