Re: CommandSecurity?

This WebDNA talk-list message is from

1997


It keeps the original formatting.
numero = 12638
interpreted = N
texte = >I thought I didn't have to put &username=[username]&password=[password] >into replace or delete contexts or forms or urls unless there were fields >in the database with exactly the same names.If your database has no fields named username/password, then WebCatalog does not 'protect' it in any way. Remote users can $Add, $Replace, $Delete, etc. unless you turn on CommandSecurity to prevent anonymous commands.So I still don't understand why your databases seem to be refusing the changes based on embedded contexts, unless you're hiding those contexts inside some kind of password-based hideif.Grant Hulbert, V.P. Engineering | ===== Tools for WebWarriors ===== Pacific Coast Software | WebCatalog Pro, WebCommerce Solution 11770 Bernardo Plaza Court | SiteEdit Pro, SiteCheck, PhotoMaster San Diego, CA 92128 | SiteGuard 619/675-1106 Fax: 619/675-0372 | http://www.smithmicro.com Associated Messages, from the most recent to the oldest:

    
  1. Re: CommandSecurity? (Grant Hulbert 1997)
  2. Re: CommandSecurity? (Kenneth Grome 1997)
  3. Re: CommandSecurity? (Kenneth Grome 1997)
  4. Re: CommandSecurity? (Grant Hulbert 1997)
  5. CommandSecurity? (Kenneth Grome 1997)
  6. CommandSecurity? (Kenneth Grome 1997)
>I thought I didn't have to put &username=[username]&password=[password] >into replace or delete contexts or forms or urls unless there were fields >in the database with exactly the same names.If your database has no fields named username/password, then WebCatalog does not 'protect' it in any way. Remote users can $Add, $Replace, $Delete, etc. unless you turn on CommandSecurity to prevent anonymous commands.So I still don't understand why your databases seem to be refusing the changes based on embedded contexts, unless you're hiding those contexts inside some kind of password-based hideif.Grant Hulbert, V.P. Engineering | ===== Tools for WebWarriors ===== Pacific Coast Software | WebCatalog Pro, WebCommerce Solution 11770 Bernardo Plaza Court | SiteEdit Pro, SiteCheck, PhotoMaster San Diego, CA 92128 | SiteGuard 619/675-1106 Fax: 619/675-0372 | http://www.smithmicro.com Grant Hulbert

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

Database wiped clean (2005) WebCat2 - Getting to the browser's username/password data (1997) Problems getting parameters passed into email. (1997) Re:WebCat for mass emailings (1997) WebCat2b13MacPlugin - nested [xxx] contexts (1997) Need example sites for seminar; will plug you too (1998) [WebDNA] Installation problems for IIS 6 (2010) Protect (1997) Forumulas.db & Variables (2002) Multi Actions (1999) Archives... (1997) MasterCounter and capitalization (1997) Web Merchant process after credit card clears (1998) WCf2 and nested tags (1997) A dynamic database. (1997) Close Databases Crash? (1998) [SearchString] usage (1997) remotely add + sign (1997) MacAuthorize order data fields WAS:How To question... (1997) Sort (2003)