On Monday 21 Jun 2010 15:33:30 Glyn Jackson wrote:
> So I want to know the best way forward in terms of a webservice, basic html
> posts? how would you open this up?

If you make a CFC-based interface to it, these are automatically available as 
standard WSDL-based web services that should work OK with anything.

> what about security? how do I restrict others from acccess this as it needs
> to be open over https?

The standard approach would be to have a login() method that returns a time-
limited (and/or locked to IP address) token, and then each other method 
accepts and validates the token.
ColdSpring's "AOP" can help here, see for instance 
http://www.rachaelandtom.info/content/slides-and-files-my-scotch-road-talk-
sotr09 for a quick ready-to-run demo 

Don't forget things like http://www.rachaelandtom.info/content/protecting-
coldfusion-applications-common-attacks though !

-- 
Tom Chiverton
Helping to continuously develop guinine cutting-edge channels as part of the 
IT team of the year 2010, '09 and '08

****************************************************

This email is sent for and on behalf of Halliwells LLP.

Halliwells LLP is a limited liability partnership registered in England and 
Wales under registered number OC307980 whose registered office address is at 
Halliwells LLP, 3 Hardman Square, Spinningfields, Manchester, M3 3EB.  A list 
of members is available for inspection at the registered office together with a 
list of those non members who are referred to as partners.  We use the word 
“partner” to refer to a member of the LLP, or an employee or consultant with 
equivalent standing and qualifications. Regulated by the Solicitors Regulation 
Authority.

CONFIDENTIALITY

This email is intended only for the use of the addressee named above and may be 
confidential or legally privileged.  If you are not the addressee you must not 
read it and must not use any information contained in nor copy it nor inform 
any person other than Halliwells LLP or the addressee of its existence or 
contents.  If you have received this email in error please delete it and notify 
Halliwells LLP IT Department on 0870 365 2500.

For more information about Halliwells LLP visit www.halliwells.co

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Order the Adobe Coldfusion Anthology now!
http://www.amazon.com/Adobe-Coldfusion-Anthology-Michael-Dinowitz/dp/1430272155/?tag=houseoffusion
Archive: 
http://www.houseoffusion.com/groups/cf-talk/message.cfm/messageid:334681
Subscription: http://www.houseoffusion.com/groups/cf-talk/subscribe.cfm
Unsubscribe: http://www.houseoffusion.com/groups/cf-talk/unsubscribe.cfm

Reply via email to