Not really paul

Because since they are accessing the document via the coldfusion server, it
gives you the chance to check that they are logged in and allowed to view
the particular file they are trying to access before you serve the document.

If you need to documents secured go for the all content in the database
option suggested by Duncan, but you'll need the users and their associated
permissions in a db also

Hth
Mark

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] 
Sent: 06 May 2004 09:44
To: [EMAIL PROTECTED]
Subject: Re: [ cf-dev ] Security for documents



Won't this defeat the object of the URL hack though.

By changing the ?docID= variable the user can see all the docs ....

perhaps I need to send the variable in another way. Maybe using form
variables?

Regars - Paul




****************************************************************************
*********************
The information contained within this e-mail (and any attachment) sent by
Birmingham City Council is confidential and may be legally privileged. It is
intended only for the named recipient or entity to whom it is addressed. If
you are not the intended recipient please accept our apologies and notify
the sender immediately, or telephone +(44) 121 303 6666. Unauthorised
access, use, disclosure, storage or copying is not permitted and may be
unlawful. Any e-mail including its content may be monitored and used by
Birmingham City Council for reasons of security and for monitoring internal
compliance with the office policy on staff use. E-mail blocking software may
also be used. Any views or opinions presented are solely those of the
originator and do not necessarily represent those of Birmingham City
Council. We cannot guarantee that this message or any attachment is virus
free or has not been intercepted and amended.

****************************************************************************
*********************


-- 
These lists are syncronised with the CFDeveloper forum at
http://forum.cfdeveloper.co.uk/
Archive: http://www.mail-archive.com/dev%40lists.cfdeveloper.co.uk/
 
CFDeveloper Sponsors and contributors:-
*Hosting and support provided by CFMXhosting.co.uk* :: *ActivePDF provided
by activepdf.com*
      *Forums provided by fusetalk.com* :: *ProWorkFlow provided by
proworkflow.com*
           *Tutorials provided by helmguru.com* :: *Lists hosted by
gradwell.com*

To unsubscribe, e-mail: [EMAIL PROTECTED]

-- 
These lists are syncronised with the CFDeveloper forum at 
http://forum.cfdeveloper.co.uk/
Archive: http://www.mail-archive.com/dev%40lists.cfdeveloper.co.uk/
 
CFDeveloper Sponsors and contributors:-
*Hosting and support provided by CFMXhosting.co.uk* :: *ActivePDF provided by 
activepdf.com*
      *Forums provided by fusetalk.com* :: *ProWorkFlow provided by proworkflow.com*
           *Tutorials provided by helmguru.com* :: *Lists hosted by gradwell.com*

To unsubscribe, e-mail: [EMAIL PROTECTED]

Reply via email to