Hello struts users

I have a really basic security problem and i would like to know what is the
best practice to resolve it.

I have an application with an authentification system and diffrent rights
for diffrent type of user. To add or remove a link/fonctionnality, we simply
declarate the element in a <s:if test=..> balise. But the problem is the
actions are still available by typing URL in bar address.

How can i fix it ?

Regards,

-- 
Stéphane Cosmeur
06 33 54 36 04

Reply via email to