Re: Role based security flaw?
- From: "Andy" <ajj3085@xxxxxxxxxxxx>
- Date: 20 Mar 2006 12:29:15 -0800
William,
#2 and #3 are easy; use PrincipalPermission. #1 requires you to add
lines of code to places... My question was trying to gauge if the
benefit would be worth the time.
Even if all those are met, its possible that the identity was
authenticated from a rogue domain (well, it might be, I'm not 100% if
that's possible).
Andy
.
- Follow-Ups:
- Re: Role based security flaw?
- From: William Stacey [MVP]
- Re: Role based security flaw?
- From: Joe Kaplan \(MVP - ADSI\)
- Re: Role based security flaw?
- References:
- Role based security flaw?
- From: Andy
- Re: Role based security flaw?
- From: Joe Kaplan \(MVP - ADSI\)
- Re: Role based security flaw?
- From: oldbear
- Re: Role based security flaw?
- From: Andy
- Re: Role based security flaw?
- From: William Stacey [MVP]
- Role based security flaw?
- Prev by Date: Re: Role based security flaw?
- Next by Date: RE: users and roles
- Previous by thread: Re: Role based security flaw?
- Next by thread: Re: Role based security flaw?
- Index(es):
Relevant Pages
|