Search Again:

Re: Unsafe E-Mail Delete method

From: Shawn Hogan
Date: Tuesday, December 31, 2002
Time: 3:43:38 pm

ISP List wrote:

> But couldn't the E-mail address itself be passed instead? Seems like it
> would be a lot safer method.. even if you are doing a translation between
> MainMenu.fp5 and the Services file..

You would have a problem of validating the user's login/password since the
login/password exist within the customer table (not the services table). So
if someone knew what they were doing, they could arbitrarily
delete/modify/change password, etc. any email as long as they knew the email
address. Another issue is there are cases where the email may not be unique
(like if an old canceled customer had the same email address).

- Shawn

----------------------------------
Shawn D. Hogan
President, Digital Point Solutions
http://www.digitalpoint.com
(858) 452-3696


---------------------------------------------------
To subscribe, unsubscribe or to search list archive
please visit http://www.optigold.com/lists/isp.html
---------------------------------------------------



Messages In This Thread:



Return to Digital Point Solutions' Home Page