• Open Menu Close Menu
  • Apple
  • Shopping Bag
  • Apple
  • Mac
  • iPad
  • iPhone
  • Watch
  • TV
  • Music
  • Support
  • Search apple.com
  • Shopping Bag

Lists

Open Menu Close Menu
  • Terms and Conditions
  • Lists hosted on this site
  • Email the Postmaster
  • Tips for posting to public mailing lists
Re: Java Client Security
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Java Client Security


  • Subject: Re: Java Client Security
  • From: Jaime Magiera <email@hidden>
  • Date: Thu, 27 Oct 2005 17:42:01 -0400

On Oct 27, 2005, at 2:49 AMGMT-04:00, Ian Joyner wrote:
But what if some hacker (sic)

Do you mean malicious programmer?

Anyway, I think I have found the answer in Chapter 6, p 140 on delegates, that the session object is a delegate of EODistributionContext and these delegate methods are called to check security before operations are allowed on the server side. These return false if the user is not logged in, which can be in a parent class of session and then in a subclass provide more fine- grained access control for checking CRED operations.

Has anyone else implemented such a JC security scheme? Does this sound like the right way to go?

Apple's JCAuthentication.framework has a shared object (AuthenticationInfo) that contains the user credentials. This can be checked from both the server and client side to validate a user. I've created a modified version of JCAuthentication that supports Groups and does checking on both the server and client side before running operations. You can probably do the same with relatively little programming.


Jaime
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Webobjects-dev mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden


References: 
 >Java Client Security (From: Ian Joyner <email@hidden>)

  • Prev by Date: Re: still the dreaded connection dictionary error...
  • Next by Date: Re: Content Management
  • Previous by thread: Re: Java Client Security
  • Next by thread: simple form question
  • Index(es):
    • Date
    • Thread