|
|
 |  |
Re: Unsafe E-Mail Delete methodFrom: Shawn Hogan Date: Tuesday, December 31, 2002
Time: 3:43:38 pmISP List wrote:
> But couldn't the E-mail address itself be passed instead? Seems like it
> would be a lot safer method.. even if you are doing a translation between
> MainMenu.fp5 and the Services file..
You would have a problem of validating the user's login/password since the
login/password exist within the customer table (not the services table). So
if someone knew what they were doing, they could arbitrarily
delete/modify/change password, etc. any email as long as they knew the email
address. Another issue is there are cases where the email may not be unique
(like if an old canceled customer had the same email address).
- Shawn
----------------------------------
Shawn D. Hogan
President, Digital Point Solutions
http://www.digitalpoint.com
(858) 452-3696
---------------------------------------------------
To subscribe, unsubscribe or to search list archive
please visit http://www.optigold.com/lists/isp.html
---------------------------------------------------
|

Return to Digital Point Solutions' Home Page |