Re: why am I getting an authenticate dialog with no [protect]?

This WebDNA talk-list message is from

2000


It keeps the original formatting.
numero = 36090
interpreted = N
texte = You may want to seriously reconsider this issue. By opening up Append to non-admin users you are opening up a huge security hole. Now, anyone with a little knowledge of WebDNA can input Append command strings that would wreak havoc on your system.The answer to this problem is to NOT open up destructive commands to non-admin users. ALWAYS use contexts instead of commands whenever possible. See the list archive for exhaustive coverage of all this.Marty Schmid Artwerkson 8/11/00 10:08 AM, Steven Jarvis at sjarvis@nwaonline.net wrote:> No, that's not the issue. I'm actually passing an Append command to the db, > and I didn't have Append in the list of allowed non-admin commands, as Chris > Allman suggest. I added Append to that list and the problem is now solved! > ------------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://search.smithmicro.com/ Associated Messages, from the most recent to the oldest:

    
  1. Re: why am I getting an authenticate dialog with no [protect]? (Steven Jarvis 2000)
  2. Re: why am I getting an authenticate dialog with no [protect]? (WebDNA Support 2000)
  3. Re: why am I getting an authenticate dialog with no [protect]? (Steven Jarvis 2000)
  4. Re: why am I getting an authenticate dialog with no [protect]? (Peter Ostry 2000)
  5. Re: why am I getting an authenticate dialog with no [protect]? (Marty Schmid 2000)
  6. Re: why am I getting an authenticate dialog with no [protect]? (Steven Jarvis 2000)
  7. Re: why am I getting an authenticate dialog with no [protect]? (WebDNA Support 2000)
  8. Re: why am I getting an authenticate dialog with no [protect]? (Steven Jarvis 2000)
  9. Re: why am I getting an authenticate dialog with no [protect]? (WebDNA Support 2000)
  10. Re: why am I getting an authenticate dialog with no [protect]? (Chris Allman 2000)
  11. Re: why am I getting an authenticate dialog with no [protect]? (Steven Jarvis 2000)
  12. Re: why am I getting an authenticate dialog with no [protect]? (Joseph D'Andrea 2000)
  13. why am I getting an authenticate dialog with no [protect]? (Steven Jarvis 2000)
You may want to seriously reconsider this issue. By opening up Append to non-admin users you are opening up a huge security hole. Now, anyone with a little knowledge of WebDNA can input Append command strings that would wreak havoc on your system.The answer to this problem is to NOT open up destructive commands to non-admin users. ALWAYS use contexts instead of commands whenever possible. See the list archive for exhaustive coverage of all this.Marty Schmid Artwerkson 8/11/00 10:08 AM, Steven Jarvis at sjarvis@nwaonline.net wrote:> No, that's not the issue. I'm actually passing an Append command to the db, > and I didn't have Append in the list of allowed non-admin commands, as Chris > Allman suggest. I added Append to that list and the problem is now solved! > ------------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://search.smithmicro.com/ Marty Schmid

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

Opinion: [input] should be called [output] ... (1997) WebCat2b13MacPlugIn - [showif][search][/showif] (1997) [WebDNA] TCPConnect w/ user:pass (2009) Setting up WebCatalog with Retail Pro data (1996) Formatted [time] inside sendmail (2002) quantity minimum problem (1997) Email template names (1997) WebCat2_Mac RETURNs in .db (1997) Mozilla/4. and Browser Info.txt (1997) [WebDNA] WebDNA on Linux (2009) WebCatalog can't find database (1997) 2nd WebCatalog2 Feature Request (1996) [CART] inside a [LOOP] (1997) [format xs] freeze (1997) Moment of Thanks (1997) numfound question (2005) Sendmail Excel attachment (2003) problems with 2 tags shakur (1997) RE: OK, here goes... (1997) Getting total number of items ordered (1997)