12-13-2012, 02:26 PM
I'm generally wary of being an armchair developer since there's only so much you can really know about a system without having worked on it yourself, but I'd strongly caution against using plain URL coding as a means for the Gateway thing.

Not only is it difficult to properly strip potentially dangerous strings (since complex characters by definition need to be permitted for character/handle names) but it represents an unnecessary security vector, one more alarming when you consider that Cryptic is potentially making server calls to Holodeck every single time this 'feature' is accessed (rather than locally cacheing results every evening or something).

If you absolutely must have a "captains database", just use a search and don't tie user input into the URL itself

