Routes and Filters

Route and filter processing is declared in the application configuration, but its deployed reachability is conditional. The route file defines explicit and fallback route families; the router assembles and scans them in order. When SPARKED is not defined, selected filters then run before controller work and after the response is produced.

[!WARNING] This page describes source-defined paths, not verified runtime behavior. Module routes depend on the deployed project-modules directory, URI segments, controller-file presence, route-file loading, and module route-discovery configuration. No successful request execution or deployment reachability was observed.

flowchart TD
    A["Config/Routes.php<br/>route declarations"] --> B["RouteCollection::getRoutes()<br/>discovery and ordered list"]
    B --> C["Router::checkRoutes()<br/>first full URI match"]
    C --> D{"Explicit route matched?"}
    D -->|Yes| E["Matched controller and route options"]
    D -->|No, auto-routing enabled| F["Router::autoRoute($uri)<br/>controller fallback"]
    E --> G["Filters::initialize()<br/>global, method, URI selections"]
    F --> G
    G --> H["If SPARKED is not defined:<br/>Filters::run($uri, 'before')"]
    H --> I["Controller and output phase"]
    I --> J["If SPARKED is not defined:<br/>Filters::run($uri, 'after')"]

Route registration and precedence

When the supplied $routes is empty or is not a usable RouteCollectionInterface, CodeIgniter's tryToRouteIt requires APPPATH . 'Config/Routes.php'; that file creates $routes for the declarations below.

imspr/app/Config/Routes.php sets the default controller namespace to App\Controllers, the default controller to Home, and automatic routing to true. It registers / with the value of DCONTROLLER after removing single-quote characters.

The same file conditionally requires Config/<ENVIRONMENT>/Routes.php when that file exists. It also conditionally enters the project-module block when ROOTPATH . PROJECT . '/modules' exists. That block reads URI segments 1 and 2, enables URI-dash translation, and compares the capitalized first segment with each module directory.

Route family Source condition Pattern shape Target and ordering
Root Always declared in the application route file / Controller value derived from DCONTROLLER
Module page controller A matching module exists and modules/<module>/Controllers/<segment-2>.php exists <module>/<controller> plus zero through four (:any) arguments Discovered module controller and method/back-references
Module root controller A matching module exists and the page-controller file does not exist <module> plus zero through four (:any) arguments Module root controller, beginning with ::index
Pages fallback Inside the project-module block, after the module loop One through five (:any) segments \Modules\Pages\Controllers\Pages::index with captured segments

RouteCollection::getRoutes() performs route discovery before returning the assembled list. Routes registered for the current HTTP verb are placed before generic routes created through add. Router::checkRoutes() then scans the list and applies a full regular-expression match; the first matching route supplies the controller, parameters, matched-route metadata, and route options.

The Pages family is added after the module loop, but the effective winner for a deployed URI still depends on the assembled patterns, HTTP verb, route-discovery configuration, and runtime directory/file tests. If explicit matching fails, the application’s automatic-routing setting allows Router to call autoRoute instead of necessarily taking the configured 404 path.

Filter selection and execution

imspr/app/Config/Filters.php maps the csrf alias to CodeIgniter\Filters\CSRF and maps startup to Filters\Startup. Its global before configuration includes startup; the csrf entry is commented out. The $methods and $filters maps are empty, so this configuration declares no method-wide or URI-pattern-specific filters.

When initialized, Filters selects entries in this order:

  1. Global filters.
  2. HTTP-method filters.
  3. URI-pattern filters.

When a matched route provides a filter option, the router exposes that option as matched-route metadata, and the request handler enables the named filter for both before and after positions. The source does not establish that a particular deployed route currently carries such an option.

During Filters::run, each selected alias is resolved to its configured class and checked against FilterInterface.

  • A before filter may replace the request and allow processing to continue.
  • A ResponseInterface result short-circuits the remaining before filters.
  • An empty result is ignored.
  • Any other non-empty result is returned to the caller.
  • After controller output is gathered, an after filter may replace the current response; processing then continues through the remaining after filters.

If the csrf alias is invoked, CSRF::before returns immediately for CLI requests. Otherwise it calls CSRFVerify. A security exception is translated into a back redirect when CSRFRedirect is enabled and the request is not AJAX; otherwise the exception is rethrown. CSRF::after has no implementation-specific work.

Updated