Re: Role based security flaw?

| #2 and #3 are easy; use PrincipalPermission. #1 requires you to add
| lines of code to places... My question was trying to gauge if the
| benefit would be worth the time.

You could use one line of code in your entry point method(s), to verify user
or throw exception, then use only attributes in your method chain after
I would make sure your public remote entry points are few and well protected
with your Verify() helper. Then after you do Impersonate, your role
security attributes should be fine.

| Even if all those are met, its possible that the identity was
| authenticated from a rogue domain (well, it might be, I'm not 100% if
| that's possible).

If that is possible, then what is more secure? So where does that leave
this? Is this a client app or a client/server. How are you authorizing
clients to the server (wse, negotiatestream/remoting, etc)?


Relevant Pages

  • Re: Cyber meltdowns
    ... > So is the $100 or so an hour that you'll charge a client when you sit them ... > down just to have a discussion in your office really going to be worth it? ... Nor will a laborer or equipment operator be responsible for making decisions ... of responsibility is just not even in the same universe. ...
  • Re: client/server design and advice
    ... I was going to initially just use python ... client application which i would run on a few pc's locally when they ... the server, request a time interval (i.e. does anything need processed? ... One thing i was wondering is if it would be worth it to use c++ for the ...
  • how much should I charge?
    ... Project studio rates seem to be around $25 for the home ... sInce the client would own it outright oftentimes I'd tack ... before I delivered it to the client. ... I wouldn't delve into this too deep until you've ascertained what the client thinks it's worth and have an idea what you ...
  • Re: Can I play LOTRO?
    ... free trial is not for Europe? ... Is there a smaller client you can DL first? ... Might be worth a try. ... Depending on how complicated you want to get, you might be able to work it ...
  • Re: Main client going to VR.
    ... LOL. ... That alone would almost make it worth it! ... Client I used to have started move to VR and used their absolute worst ...