I am aware that people can manipulate the referer, but as the WMS is currently configured, anyone can just use the service and embed it into their own application, which would not only cause additional traffic on my server, but would also be problematic from a copyright point of view.

Unfortunately, in Europe, geodata isn't free, and therefore we have to protect it, at least to a certain extent.

I am also aware that the images end up in the cache and anyone can copy them, but the referer thing is not to prevent people stealing single images (I don't care about that), but to prevent people building bigger or even commercial services around my WMS, without asking the data distributor for permission.

If I am unable to secure the WMS to a certain extent, I am not allowed to publish the service, which would be sad.

Anyway, it would be useful, if Batik would send the referer data, also for webserver logfile statistics.

Andreas

Michael Mosmann wrote:

Am Freitag, den 11.08.2006, 12:52 +0200 schrieb Andreas Neumann:
Hello,

I have a way to restrict this in Apache by using the referer information. If a request has been made from my own domain (or specific files), access is granted, otherwise not.

This is only a soft protection, cause proxy or application can
manipulate this header entry. So if i want to access your service i
would fake this header information.

mm:)



---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



--
----------------------------------------------
Andreas Neumann
Institute of Cartography
ETH Zurich
Wolfgang-Paulistrasse 15
CH-8093  Zurich, Switzerland

Phone: ++41-44-633 3031, Fax: ++41-44-633 1153
e-mail: [EMAIL PROTECTED]
www: http://www.carto.net/neumann/
SVG.Open: http://www.svgopen.org/
Carto.net: http://www.carto.net/


---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to