Re: Security for malls with different webmasters

This WebDNA talk-list message is from

1998


It keeps the original formatting.
numero = 16658
interpreted = N
texte = >I am evaluating WebCatalog for use in a small mall. The mall consists of >several shops. Each shop has its own directory, templates and database. > >Every one of the shops has its own webmaster with FTP access to his (and >only his) directory. > >The problem is: Every webmaster has full rights to his directory (to >update his own sites). This means he could write a template that can >manipulate the data in the database in another directory/shop, couldn't >he?Yes.>Is there any way to prevent that and still allow full access to the >directory?No.>What about commands like CopyFile or DeleteFile? Can they >be switched off completely or kept from working outside their parent >directory?No.WebCatalog is far too powerful for you to be allowing anyone else to modify or upload WebDNA templates directly. To be secure, you cannot allow your webmasters to modify ANY WebDNA in existing templates, or to upload new templates with WebDNA code in them.If you want your webmasters to have the ability to change their sites while maintaining security for your server and all the sites running on it, then you must manually approve each new page that gets sent to you -- before you put it on your server. That generally means having them email their new templates to you, then you can review the code to be sure it's non-destructive before putting the file on the server.Sincerely, Ken Grome 808-737-6499 WebDNA Solutions mailto:ken@webdna.net http://www.webdna.net Associated Messages, from the most recent to the oldest:

    
  1. Re: Security for malls with different webmasters (Jack Baty 1998)
  2. Re: Security for malls with different webmasters (PCS Technical Support 1998)
  3. Re: Security for malls with different webmasters (Kenneth Grome 1998)
  4. Security for malls with different webmasters (Rainer Hofmeister 1998)
  5. Re: Security for malls with different webmasters (Olin Lagon 1998)
>I am evaluating WebCatalog for use in a small mall. The mall consists of >several shops. Each shop has its own directory, templates and database. > >Every one of the shops has its own webmaster with FTP access to his (and >only his) directory. > >The problem is: Every webmaster has full rights to his directory (to >update his own sites). This means he could write a template that can >manipulate the data in the database in another directory/shop, couldn't >he?Yes.>Is there any way to prevent that and still allow full access to the >directory?No.>What about commands like CopyFile or DeleteFile? Can they >be switched off completely or kept from working outside their parent >directory?No.WebCatalog is far too powerful for you to be allowing anyone else to modify or upload WebDNA templates directly. To be secure, you cannot allow your webmasters to modify ANY WebDNA in existing templates, or to upload new templates with WebDNA code in them.If you want your webmasters to have the ability to change their sites while maintaining security for your server and all the sites running on it, then you must manually approve each new page that gets sent to you -- before you put it on your server. That generally means having them email their new templates to you, then you can review the code to be sure it's non-destructive before putting the file on the server.Sincerely, Ken Grome 808-737-6499 WebDNA Solutions mailto:ken@webdna.net http://www.webdna.net Kenneth Grome

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

[replaceChars] would be nice ... (1997) Emailer setup (1997) PIXO support (1997) SKU lookup (1997) Bad card db - *mislabled post* (1999) FREE Web Server Monitor FREE (1997) New Site Announcement (1998) Grant, please help me ... (1997) 404s - Apache vs. WebDNA (2008) the comparison character \ (2000) timing out? (1997) Desperatly seeking (2000) Math (1997) hiding return characters (2000) insecure client not shown (1998) [OT] I am old. (2003) Serious WebDNA issue (2006) Extended [ConvertChars] (1997) Multiple prices (1997) Security Question (1997)