Re: WebCat2 beta 11 - new prefs ...
This WebDNA talk-list message is from 1997
It keeps the original formatting.
numero = 10337
interpreted = N
texte = >I assume that CommandSecurity also controls all the other commands too? OR>does this one deal only with the Append command?It controls all commands. Append was just example. Look at the preferences that ship with b11 for our recommended setup.>If it controls all commands, then setting CommandSecurity to T>effectively eliminates everyone but me from appending, replacing, and>deleting even if they enter the username and password that appears in the>record they are trying to append, replace, or delete - is this correct?>>I don't want that on my site, so I think I need to set CommandSecurity to>F ...No, we designed this feature just for you, so you're required to use it even if no one else does ;)Your setting should be CommandSecurity=T, CommandsAllowed=Replace, Delete, Search, ShowPage, etc. Notice the absence of Append from this list. This means remote unauthorized people cannot $Append to your databases with a URL. KEY CONCEPT: When you want anonymous people to Append to your databases, do it with an embedded [Append] context on a page that has [protect] of some kind on it. The preference only affects $Command, not embedded contexts.Ther idea here is that you can still achieve anonymous Appends using embedded [Append] contexts in a page...but now you have more control over it because you decide which databases get appended to. The only problem with $Append commands is that someone can homebrew a URL that appends records to any database of their choosing...not possible when you use embedded appends.Grant Hulbert, V.P. Engineering | Tools for WebWarriorsPacific Coast Software | WebCatalog, WebCommerce Solution11770 Bernardo Plaza Court, #462 | SiteEdit, SiteCheck, PhotoMasterSan Diego, CA 92128 |619/675-1106 Fax: 619/675-0372 | http://www.smithmicro.com
Associated Messages, from the most recent to the oldest:
>I assume that CommandSecurity also controls all the other commands too? OR>does this one deal only with the Append command?It controls all commands. Append was just example. Look at the preferences that ship with b11 for our recommended setup.>If it controls all commands, then setting CommandSecurity to T>effectively eliminates everyone but me from appending, replacing, and>deleting even if they enter the username and password that appears in the>record they are trying to append, replace, or delete - is this correct?>>I don't want that on my site, so I think I need to set CommandSecurity to>F ...No, we designed this feature just for you, so you're required to use it even if no one else does ;)Your setting should be CommandSecurity=T, CommandsAllowed=Replace, Delete, Search, ShowPage, etc. Notice the absence of Append from this list. This means remote unauthorized people cannot $Append to your databases with a URL. KEY CONCEPT: When you want anonymous people to Append to your databases, do it with an embedded
[append] context on a page that has
[protect] of some kind on it. The preference only affects $Command, not embedded contexts.Ther idea here is that you can still achieve anonymous Appends using embedded
[append] contexts in a page...but now you have more control over it because you decide which databases get appended to. The only problem with $Append commands is that someone can homebrew a URL that appends records to any database of their choosing...not possible when you use embedded appends.Grant Hulbert, V.P. Engineering | Tools for WebWarriorsPacific Coast Software | WebCatalog, WebCommerce Solution11770 Bernardo Plaza Court, #462 | SiteEdit, SiteCheck, PhotoMasterSan Diego, CA 92128 |619/675-1106 Fax: 619/675-0372 | http://www.smithmicro.com
Grant Hulbert
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
popups, netscape vs explorer (1997)
WC Database Format (1997)
Looking for WebCat developer/contractor (2000)
Another IfThenElse question.. (2003)
Odd request (2003)
OOPS (was RE: Email Scavengers) (2003)
HELP WITH DATES (1997)
RE: [WebDNA] a major shift in strategy? (2008)
JavaScript form question (2001)
Strange Form Occurrence on Log In Pages (2005)
RE: Loss in form (1998)
Server Takes 2 Hours to Boot UP (2004)
founditem align (1998)
Properly coded search fails ... (2003)
[SetHeader] docs? (1997)
Need help with form (1998)
Appending space (1998)
IIS4b2 and WebCatalog b19 (1997)
Re:listfiles-looking for slick solution (1997)
E-Mailer (WebCatb15acgiMac) (1997)