|
Re: Controlling access to pdf/doc files: msg#00089security.web-applications
Do not allow direct access to the file itself. Create the file dynamically, or read it from a location outside the web root, via a servlet/app that checks the validity of the session. It is not difficult to supply headers to indicate the content-disposition, which tells the browser to try to save the file, and can even provide a useful file name, rather than the name of the servlet. Rogan Sangita Pakala wrote: Hi, -- "Using encryption on the Internet is the equivalent of arranging an armored car to deliver credit card information from someone living in a cardboard box to someone living on a park bench." - Gene Spafford |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | RE: Controlling access to pdf/doc files: 00089, Harper.Matthew |
|---|---|
| Next by Date: | RE: code analysis for c#?: 00089, Arjun Pednekar |
| Previous by Thread: | Re: Controlling access to pdf/doc filesi: 00089, chasd |
| Next by Thread: | RE: Controlling access to pdf/doc files: 00089, Paulus Widodo |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |