Skip to main content
This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal

Notes/Domino 6 and 7 Forum

Notes/Domino 6 and 7 Forum


  

PreviousPrevious NextNext


~Anita Xanponevitchakoi 21.Jan.04 08:50 PM a Web browser
Domino Designer All Releases All Platforms


Hi,

I'm trying to design a Web-based application that requires manual user authentication based against security values for users located in a SQL table. In other words, the user starts from a login page, enters their username/password, and then a WQS agent connects to the SQL table and checks to see whether the user exists. If the user exists, and their security fields permit it, they are taken to a Welcome page, where the user can generate various reports from forms in the target database with other agents. If they don't authenticate, they are re-directed back to the login form with a message that their username/password is incorrect.

However, there is a very big hole in my solution: anyone can type a URL that accesses a particular form or agent in my target database (e.g. "http://myserver/targetDB/RestrictedForm?OpenForm&param1=ABC" or "http://myserver/targetDB/RestrictedAgent?OpenAgent&param1=ABC" and bypass my security check. How can I modify my forms and agents to block users that haven't gone through my login form and authenticated?

Any suggestions are appreciated!






help with manual user authenticatio... (~Anita Xanponev... 21.Jan.04)
. . Your probable best bet would be to ... (~Dan Elhipister... 21.Jan.04)
. . . . RE: Your probable best bet would be... (~Anita Xanponev... 21.Jan.04)
. . . . . . here is a link to a program in the ... (~Dan Elhipister... 22.Jan.04)





  Document options
Print this pagePrint this page

 Search this forum

  Forum views and search
Date (threaded)
Date (flat)
With excerpt
Category
Platform
Release
Advanced search

 RSS feedsRSS
All forum posts RSS
All main topics RSS