Forums

B137191 : Security Strategy into web application isn't secure!

Last post 10/24/2009 10:41 AM by James Smyth. 35 replies.
Support Center Article: B137191
1 2 3 Next
Sort Posts: Previous Next
  • Jascha

    B137191 : Security Strategy into web application isn't secure!

    6/12/2009 7:01 AM
    • Top 50 Contributor
    • Joined on 5/4/2007
    • Posts 935

    I think it is about time the security system in XAF is thoroughly overhauled. Perhaps it needs to be integrated into the data layer instead? Add the fact that security does not get applied to reporting at all and you have a pretty useless module (particularly in win apps where users can create reports themselves and see everyting they are supposedly not allowed to see).

    DX?

    Jascha

  • Chloe Anfield

    Re: B137191 : Security Strategy into web application isn't secure!

    6/12/2009 7:10 AM
    • Top 150 Contributor
    • Joined on 10/22/2008
    • Herts, UK
    • Posts 144
  • Martin Praxmarer [DX-Squad]

    Re: B137191 : Security Strategy into web application isn't secure!

    6/12/2009 7:25 AM
    • Top 50 Contributor
    • Joined on 3/16/2009
    • Tirol, Austria
    • Posts 534
  • E3i Tecnologia Ltda

    Re: B137191 : Security Strategy into web application isn't secure!

    6/12/2009 9:43 AM
    • Top 500 Contributor
    • Joined on 6/21/2007
    • Posts 55

    +1

    And I have more suggestions...

    - Permission by user
    - Recursive Roles
    - Expiration Date for these permissions
    - Security by Web Service

    I already implemented these suggestions, but will be good see these features as default...

    Edited: Security by WebService only returns the connection string if user/pass is correct...

  • Marcello

    Re: B137191 : Security Strategy into web application isn't secure!

    6/12/2009 11:49 AM
    • Top 75 Contributor
    • Joined on 11/10/2008
    • Posts 274

    Of course I aggregate to you Jascha! I hope that the bug I reported is resolved quickly because it's very serious!

    Marcello

  • Manel Fernandez

    Re: B137191 : Security Strategy into web application isn't secure!

    6/12/2009 12:50 PM
    • Not Ranked
    • Joined on 5/4/2008
    • Posts 27
  • Robert Fuchs

    RE: B137191 : Security Strategy into web application isn't secure!

    6/12/2009 4:38 PM
    • Top 25 Contributor
    • Joined on 5/4/2007
    • Tirol, Austria
    • Posts 2,454

    +1, tracked!

    Further, please finally add security on porperty level !!!!!!!!!!!!!!!!!!!!!!!!!!

    Robert

     

  • Gary L Cox Jr [DX-Squad]

    Re: RE: B137191 : Security Strategy into web application isn't secure!

    6/16/2009 11:49 AM
    • Top 50 Contributor
    • Joined on 9/9/2007
    • Austin, Tx
    • Posts 811

    I agree, it would also be nice if one could restrict access to an object such as Reports.  Some clients may not want a group of users to print a full client list with all their customers data that an employee could steal.  An administrator might want to allow a User Role to see reports, but not report (A, B, and C).

  • Jascha

    RE: B137191 : Security Strategy into web application isn't secure!

    7/2/2009 4:17 AM
    • Top 50 Contributor
    • Joined on 5/4/2007
    • Posts 935

    Marcello's latest comment: "If you don't guarantee security then XAF is tool only for small projects without user account protection! Our client are very worried for this problem of security."

    Precisely - DX please take this seriously and as a high priority. The security system in its current state is not strong enough for any scenario where security beyond logging in is a requirement (of which there are many) and consequently XAF is very limited in its reach while this remains the case. If you intend XAF to be a serious tool in the business application marketplace then this cannot be ignored or left as TBD because it is not easy to do.

    Jascha

  • Ralph Rutschmann

    Re: RE: B137191 : Security Strategy into web application isn't secure!

    7/2/2009 5:09 AM
    • Top 100 Contributor
    • Joined on 12/14/2007
    • Posts 263

     ++1!

    Ralph

  • Tolis Bekiaris [DX-Squad]

    Re: RE: B137191 : Security Strategy into web application isn't secure!

    7/2/2009 5:44 AM
    • Top 50 Contributor
    • Joined on 6/21/2007
    • Posts 592
  • Robert Fuchs

    RE: Re: RE: B137191 : Security Strategy into web application isn't secure!

    7/2/2009 9:39 AM
    • Top 25 Contributor
    • Joined on 5/4/2007
    • Tirol, Austria
    • Posts 2,454

    Dan,

    if you are saying - and these are your own words - that you "cannot guarantee that data is totally secured and there is no way to read protected content" then please immediately take this down from your website because it is a blatant lie and a deception of your customers:
    http://www.devexpress.com/Xaf/Security.aspx : "Designed with security in mind. XAF is secure by design."

    Thank you.

     

  • Julian Bucknall (DevExpress)

    Re: B137191 : Security Strategy into web application isn't secure!

    7/2/2009 7:36 PM
    • Top 25 Contributor
    • Joined on 4/5/2006
    • Colorado
    • Posts 1,842
    Jascha

    On Fri, 12 Jun 2009 11:01:09 +0000 (UTC), "Jascha" <> wrote:

    >I think it is about time the security system in XAF is thoroughly
    >overhauled. Perhaps it needs to be integrated into the data layer
    >instead?

    As stated in the issue, we recognize this and are working on it. I'm
    going to guess that it'll be a breaking change, but I'm by no means
    the expert on what needs to be done.

    --
    Cheers, Julian

    -----------------------------------------------------------
    Julian M Bucknall
    CTO, Developer Express, www.devexpress.com
    julianb@devexpress.com

    Personal blog at http://www.boyet.com
    Company blog at http://community.devexpress.com/blogs/ctodx
    Author of "Tomes of Delphi: Algorithms and Data Structures"
    Read my articles in PCPlus every month
    -----------------------------------------------------------
    |
  • Julian Bucknall (DevExpress)

    Re: B137191 : Security Strategy into web application isn't secure!

    7/2/2009 7:40 PM
    • Top 25 Contributor
    • Joined on 4/5/2006
    • Colorado
    • Posts 1,842
    Jascha

    On Thu, 2 Jul 2009 08:17:21 +0000 (UTC), "Jascha" <> wrote:

    >DX please take this seriously and as a high priority.

    Of course we are. In fact, nowhere that I can see have we said that we
    are not taking it seriously or have decided not to prioritize it. I
    would imagine that it's a lot of work, but then again I argue from a
    theoretical viewpoint.

    --
    Cheers, Julian

    -----------------------------------------------------------
    Julian M Bucknall
    CTO, Developer Express, www.devexpress.com
    julianb@devexpress.com

    Personal blog at http://www.boyet.com
    Company blog at http://community.devexpress.com/blogs/ctodx
    Author of "Tomes of Delphi: Algorithms and Data Structures"
    Read my articles in PCPlus every month
    -----------------------------------------------------------
    |
  • Julian Bucknall (DevExpress)

    Re: B137191 : Security Strategy into web application isn't secure!

    7/2/2009 7:45 PM
    • Top 25 Contributor
    • Joined on 4/5/2006
    • Colorado
    • Posts 1,842
    Robert

    As has been said in the support center issue thread, we are working on
    solving for this particular scenario. This would presumably involve
    moving the security down into the business layer rather than the UI,
    or even into the data layer/database. Please give us some time to make
    sure that we get this new design right and minimize the breaking of
    code.

    Thanks for your patience.

    --
    Cheers, Julian

    -----------------------------------------------------------
    Julian M Bucknall
    CTO, Developer Express, www.devexpress.com
    julianb@devexpress.com

    Personal blog at http://www.boyet.com
    Company blog at http://community.devexpress.com/blogs/ctodx
    Author of "Tomes of Delphi: Algorithms and Data Structures"
    Read my articles in PCPlus every month
    -----------------------------------------------------------
    |
1 2 3 Next
More from DevExpress
Live Chat
Have a pre-sales question?
Need assistance with your evaluation?
We are here to help.
Chat is one of the many ways you can contact members of the DevExpress Team. We are available Monday-Friday between 8:30am and 5:00pm Pacific Time.
If you need additional product information, require pre-sales assistance, or want help with your order, write to us at info@devexpress.com or call us at
+1 (818) 844-3383.