Developing ColdFusion MX Applications with CFML
|
|
Securing Applications
|
ColdFusion security features
ColdFusion provides scalable, granular security for building and deploying your ColdFusion applications. ColdFusion provides following types of security resources:
- Development ColdFusion MX Administrator is protected by a password. Additionally, you can specify a password for access to data sources from Macromedia Dreamweaver MX. For more information on configuring Administrator security passwords, see the ColdFusion MX Administrator online Help. This chapter does not these passwords. For more information see the Administrator Help.
- Resource The ColdFusion MX Administrator can limit access to ColdFusion resources, including selected tags and functions, data sources, files, and host addresses, based on the location of your ColdFusion pages. You can confine applications to secure areas, thereby flexibly restricting the access that the application has to resources.
- User ColdFusion applications can require users to log in to use application pages. You can assign users to roles (sometimes called groups); ColdFusion pages can determine the logged-in user's role or ID and selectively determine what to do based on this information.
Note: You can also use the cfencode
utility, located in the cf_root/bin directory, to obfuscate ColdFusion pages that you distribute. Although this technique cannot prevent determined hackers from determining the contents of your pages, it does prevent inspection of the pages.
Comments