Hi there, mailing list,

 

We have a customer sending us data with sensitive information. The most
convenient way for us is to receive the complete data set and applying a
filter in the mapfile.

 

The layer definition looks like this:

LAYER

                               NAME Traseer

                               GROUP TelMe

                               TYPE LINE

                               DATA "TM_Nett/TM_Traces"

                               FILTER('[type]' != "Bru")

                               #Styling and more etc....

END

 

This works flawlessly using PHP Mapscript and the mapserver WMS service. The
data is not accessible. The problem occurs when querying by WFS. The
Mapserver WFS service seems to omit the FILTER information and opens up for
selecting items with the type “Bru”, which is a serious security flaw. 

 

I’d consider this as a bug, although I’m not certain. If anyone please can
confirm this, or show me how to make mapserver filter data in WFS as well,
I’d be much obliged.

 

Best Regards,

Håkon

_______________________________________________
mapserver-users mailing list
[email protected]
http://lists.osgeo.org/mailman/listinfo/mapserver-users

Reply via email to