Re: [WebDNA] Security best practice

This WebDNA talk-list message is from

2009


It keeps the original formatting.
numero = 101851
interpreted = N
texte = Regarding security, one thing that is new in CICADA is the ability to encrypt (as an option) certain sensitive orderfile information.. such as "accountnum". This is one area that I would like for people to test, because I have only had the chance to test it marginally. So far, my tests are that it works. ;-) For example, (only for CICADA owners) activate an orderfile encryption (in the admin pages) and, on a template, do a : [setheader cart=[cart]]accountnum=4111111111111111[/setheader] (remember to have the "ShoppingCarts" directory in the same root as your test template) If you look in the orderfile that was created after hitting that template ("less " in a terminal window), you will see your encrypted accountnum value. Then doing a: [orderfile cart=[cart]] [accountnum] [/orderfile] The encrypted value is magically decrypted and viewable. However, I have not, for example, had a chance to test this under heavy load, or, for example, initiating this on a server with existing sites that use the orderfile tags... but, it looks like a nice feature that SMSI created under the radar so far and it would be really cool if this feature worked on existing sites that use the orderfile tags. I will have time to test this more thoroughly in the future, but if someone else has the means and time, please report back your findings! Donovan -- Donovan D. Brooke PH: 1 (608) 770-3822 ------------------------------------------------ VP WebDNA Software Corporation 16192 Coastal Highway Lewes, DE 19958 Associated Messages, from the most recent to the oldest:

    
  1. Re: [WebDNA] Security best practice (Donovan Brooke 2009)
  2. Re: [WebDNA] Security best practice (Terry Wilson 2009)
  3. Re: [WebDNA] Security best practice (Clint Davis 2009)
  4. Re: [WebDNA] Security best practice (Terry Wilson 2009)
  5. Re: [WebDNA] Security best practice (Donovan Brooke 2009)
  6. Re: [WebDNA] Security best practice (Donovan Brooke 2009)
  7. [WebDNA] Security best practice ("Tom Duke" 2009)
Regarding security, one thing that is new in CICADA is the ability to encrypt (as an option) certain sensitive orderfile information.. such as "accountnum". This is one area that I would like for people to test, because I have only had the chance to test it marginally. So far, my tests are that it works. ;-) For example, (only for CICADA owners) activate an orderfile encryption (in the admin pages) and, on a template, do a : [setheader cart=[cart]]accountnum=4111111111111111[/setheader] (remember to have the "ShoppingCarts" directory in the same root as your test template) If you look in the orderfile that was created after hitting that template ("less " in a terminal window), you will see your encrypted accountnum value. Then doing a: [orderfile cart=[cart]] [accountnum] [/orderfile] The encrypted value is magically decrypted and viewable. However, I have not, for example, had a chance to test this under heavy load, or, for example, initiating this on a server with existing sites that use the orderfile tags... but, it looks like a nice feature that SMSI created under the radar so far and it would be really cool if this feature worked on existing sites that use the orderfile tags. I will have time to test this more thoroughly in the future, but if someone else has the means and time, please report back your findings! Donovan -- Donovan D. Brooke PH: 1 (608) 770-3822 ------------------------------------------------ VP WebDNA Software Corporation 16192 Coastal Highway Lewes, DE 19958 Donovan Brooke

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

ACGI processing for .html (1997) MacAuthorize order data fields WAS:How To question... (1997) Email notification to one of multiple vendors ? (1997) Questions To Answer (1997) WebCatalog2 Feature Feedback (1996) hideif/showif causes error if wrapped around searches (2003) Webcat run amuk (2002) WCS Newbie question (1997) date math (2005) Custom Shipping Charges (1997) Using Plug-In while running 1.6.1 (1997) Re:2nd WebCatalog2 Feature Request (1996) [subtotal] and others (1997) Secure server question (1997) [Sum] function? (1997) Commitdatabase tag (1998) anyone using iBill on MacOS/WebStar (2000) WordBreak Qestion (1998) syntax question, not in online refernce (1997) Date as number and Cart partially explained (2001)