HighTechTalks DotNet Forums  

Security Question

Dotnet Framework (Component Services) microsoft.public.dotnet.framework.component_services


Discuss Security Question in the Dotnet Framework (Component Services) forum.



Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old   
Bill Smith
 
Posts: n/a

Default Security Question - 04-11-2005 , 02:45 AM






I current have a COM+ object running under a Privileged account which
performs sensitive operations. A webpages front end is setup to access this
object. The web server is set to impersonate the current user and all the
security checks are preformed within the webpage code. The com object
security is set to a security group which all users accessing the webpage
are in.

The question I have is do I have to do all the security checks I do in the
front end webpage again on the COM+ object? My worry is if some how one of
the users could bypass the front end and get directly at the COM+ object.
The box would be locked down but it that enough? Any help would be
gratefully I cant seem to find any best practices for this situation.

Thanks
Bill



Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Powered by vBulletin Version 3.5.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.