Jump to content
View in the app

A better way to browse. Learn more.

FMForums.com

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Just found a nasty security flaw

Featured Replies

Since the beginning I'm hiding the status area in all of my solutions. All the functionality that is needed is built in the interface.

 

I just found out that on Mac one can simply right-click the title bar and choose 'Customize Toolbar...' And voilà: the status bar appears... and it's going to stay.

 

I don't know if it's been like that in earlier versions. I suspect that it is. Probably it's an OS thing, so I doubt that FMI can fix this.

 

Now I need to revise all my solutions to add the script step 'Hide Toolbars' to all relevant scripts. I also have to empty the layout menu.

 

Don't know how it is on Windows...

 

post-66194-0-05086800-1393341584_thumb.p

Right clicking the title bar does nothing in windows.

  • Author

What is the default action for customizing toolbars in Windows?

What is the default action for customizing toolbars in Windows?

 

Not sure what you mean

I submitted a bug report to FileMaker - i haven't tested yet but what permission level access does the users have also you may try to deployed custom menus - these in the short term may lessen the unintended impact.

This is why the standard best practice is to handle security using FileMaker's security features, with user interface controls only playing a supporting role. Short of best practices, custom menus mitigate the amount of damage users can do with this. (After all, if you weren't using custom menus already, showing the toolbar doesn't really expand what users can do, only the discoverability of what they can do.)

It may well be a flaw. But it is not a security flaw.

The toolbars may be exposed but they can be rendered essentially inert via the settings in the Privilege Set.  This is one of the reasons that the default setting for a new Privilege Set is "Minimum" menu availability.

 

The UI is not part of the security schema.

 

Perhaps I can say more at a later time.  Headed out the door to a conference now.

 

Steven

  • Author

I admit it's not a security flaw. Now I have emptied the layout dropdown in all my solutions, and the rest was already disabled by clever custom menus.

 

But it is a pain in the xxx. At the bottom 25 pts of the layout area disappears. Essential buttons could be placed there. The window could have the zooming option disabled. Hours of meticulous designing are wasted.

 

Maybe I'm exaggerating, but I consider this a seriuous bug.

I understand your frustration and aggravation.  However, the UI is not part of the security schema.

 

Just because there is no Print menu item does not mean I cannot print a record.

 

Just because there is no New Record menu item does not mean I cannot create a new record.

 

Just because there is no Delete Record menu item does not mean I cannot delete a record.

 

All these elements and many others as well are controlled by the privilege bit settings in the Privilege Set.  Some apply only to the file in which they are defined, e.g. Print.  Others apply across files in a solution, e.g. edit records.

 

Steven

Create an account or sign in to comment

Important Information

By using this site, you agree to our Terms of Use.

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.