Jump to content
Server Maintenance This Week. ×

Managing user accounts on layouts


This topic is 3264 days old. Please don't post here. Open a new topic instead.

Recommended Posts

Hi all

I've been looking at demo CRM solutions for a company I'm working with and was particularly interested in BusinessMan. While looking at their solution I noticed that they have their accounts and privilege sets managed on a layout which alleviated the need for the user to need access the native FileMaker Security module. Is this a plug-in they might be using or perhaps some more complex scripting which updates a "user" table and the security, respectively?

I'm wanting to allow managers to add and disable user accounts but prevent them from needing to access the security module since they could potentially alter the state of my administrator account. 

Link to comment
Share on other sites

This is a prescription for a vulnerability disaster. I'll be showing this particular vulnerability in my DevCon presentation.

There are script steps that permit adding and deleting Accounts without accessing the Manage Security section of the database.  I would definitely use these instead of the system these people put into their file.

 

Steven

Link to comment
Share on other sites

This topic is 3264 days old. Please don't post here. Open a new topic instead.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.