RE: [ACFUG Discuss] security in CFC

2007-07-23 Thread John Mason
ED] [mailto:[EMAIL PROTECTED] On Behalf Of Dean H. Saxe Sent: Monday, July 23, 2007 8:50 PM To: discussion@acfug.org Subject: Re: [ACFUG Discuss] security in CFC What value does hashing play? A hashed password compromised in this case is as good as one that is not hashed, they are equals here. This

Re: [ACFUG Discuss] security in CFC

2007-07-23 Thread Douglas Knudsen
*On Behalf Of *John Mason *Sent:* Monday, July 23, 2007 4:59 PM *To:* discussion@acfug.org *Subject:* RE: [ACFUG Discuss] security in CFC >CFLOGIN can also get its authentication from web server basic security Interesting, I actually handle the security on my web services differently but I hadn&#x

Re: [ACFUG Discuss] security in CFC

2007-07-23 Thread Dean H. Saxe
Monday, July 23, 2007 4:59 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] security in CFC >CFLOGIN can also get its authentication from web server basic security Interesting, I actually handle the security on my web services differently but I hadn't thought of that.

RE: [ACFUG Discuss] security in CFC

2007-07-23 Thread John Mason
thers cfcs thereby using the roles attributes. John [EMAIL PROTECTED] _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Charlie Arehart Sent: Monday, July 23, 2007 6:47 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] security in CFC Sure, and given what Dean said

RE: [ACFUG Discuss] security in CFC

2007-07-23 Thread Charlie Arehart
07 4:59 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] security in CFC >CFLOGIN can also get its authentication from web server basic security Interesting, I actually handle the security on my web services differently but I hadn't thought of that. John [EMAIL PROTECTED]

RE: [ACFUG Discuss] security in CFC

2007-07-23 Thread Charlie Arehart
arlie _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dean H. Saxe Sent: Monday, July 23, 2007 4:45 PM To: discussion@acfug.org Subject: Re: [ACFUG Discuss] security in CFC Charlie, I agree with most of your answer, but I'd really hesitate to use HTTP BASIC authenti

RE: [ACFUG Discuss] security in CFC

2007-07-23 Thread John Mason
Arehart Sent: Monday, July 23, 2007 4:43 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] security in CFC Doug, I don't know the answer, but here's a thought: the roles are set by the CFLOGINUSER tag, and there's nothing that says that has to be set in application.cfm/cfc

Re: [ACFUG Discuss] security in CFC

2007-07-23 Thread Dean H. Saxe
ion of a CFFUNCTION. Just a thought. Someone may know better. /charlie From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Douglas Knudsen Sent: Monday, July 23, 2007 3:08 PM To: discussion@acfug.org Subject: Re: [ACFUG Discuss] security in CFC are roles actually invoked when a cf

RE: [ACFUG Discuss] security in CFC

2007-07-23 Thread Charlie Arehart
July 23, 2007 3:08 PM To: discussion@acfug.org Subject: Re: [ACFUG Discuss] security in CFC are roles actually invoked when a cfc is set to remote access? Since application.cfc/cfm are NOT invoked, I thought perhaps the roles would be useless for this. DK On 7/21/07, John Mason <[EMAIL

RE: [ACFUG Discuss] security in CFC

2007-07-23 Thread John Mason
: discussion@acfug.org Subject: Re: [ACFUG Discuss] security in CFC are roles actually invoked when a cfc is set to remote access? Since application.cfc/cfm are NOT invoked, I thought perhaps the roles would be useless for this. DK On 7/21/07, John Mason <[EMAIL PROTECTED]> wrote: Lance, natural

Re: [ACFUG Discuss] security in CFC

2007-07-23 Thread Douglas Knudsen
ject:* [ACFUG Discuss] security in CFC Any One I'm looking for any documentation on how to handle security in CFC and webservices ,best practices stuff Thk Lance - Annual Sponsor - Figleaf Software <http://www.figl

RE: [ACFUG Discuss] security in CFC

2007-07-21 Thread John Mason
Sorry about the wording. I'm multitasking as usual and should have proof read this. John _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John Mason Sent: Saturday, July 21, 2007 12:52 PM To: discussion@acfug.org Subject: RE: [ACFUG Discuss] security in CFC

RE: [ACFUG Discuss] security in CFC

2007-07-21 Thread John Mason
To: discussion@acfug.org Cc: [EMAIL PROTECTED] Subject: [ACFUG Discuss] security in CFC Any One I'm looking for any documentation on how to handle security in CFC and webservices ,best practices stuff Thk Lance -

[ACFUG Discuss] security in CFC

2007-07-21 Thread Lance Knight
Any One I'm looking for any documentation on how to handle security in CFC and webservices ,best practices stuff Thk Lance - Annual Sponsor FigLeaf Software - http://www.figleaf.com To unsubscribe from this list, manag