[mapguide-users] Fusion security (or lack of)

Andrew DeMerchant andrew.demerchant at gemtec.ca
Tue May 27 14:21:34 EDT 2008


It'd be awfully nice if you could actually just have it set up the same 
way as the dwf/ajax viewers though - to ask for a login....or at least, 
have a setting somewhere so you could toggle logging in (and perhaps set 
which user is used for auto-logging in). Right now, I'm using a 
combination of the Mapguide Studio demo, and MapStudio OS for my 
projects. MSOS is the only one that supports making a fusion layout. 
Basically, there needs to be a way for people (like me) who are using 
the Studio apps, to set up the security for fusion, without having to 
deal with coding and session ids, etc. Until someone makes some sort of 
login option for fusion, I'm simply not going to be able to use it in my 
projects - as nice as it looks. I suspect that I'm not alone in that.


Kenneth Skovhede, GEOGRAF A/S wrote:
> I don't know how to get fusion to ask the user for a password.
> But you can set a password for the "Anonymous" user in the Site 
> Administrator.
> You can also change the permissions on the root folder.
>
> In any case, the problem is that the user viewing the map, must also 
> be able to read the data.
> If you use the same user for viewing all maps, that user has access to 
> all mapping data.
> It is not required that the username/password is avalible on the 
> client (it can use the pre-created sessionid).
> But with the sessionid, the user can retrieve the same data, so it is 
> basically a matter of starting a map, and retriving the session id.
> Regards, Kenneth Skovhede, GEOGRAF A/S
>   
>
>
> Andrew DeMerchant skrev:
>> I've asked about this before - it seems as though there basically is 
>> no security when it comes to Fusion maps. Is there a way to force a 
>> login when viewing a Fusion map? Also, am I right in thinking that 
>> basically, a Fusion app could act as a backdoor to any 'secured' 
>> dwf/ajax app? It seems as though you can access any map in your 
>> library (or someone else's), in theory...I'm more concerned with 
>> figuring out a way to force a login, at the moment - but this all may 
>> be something to consider heavily for the next release.
>>
>> Andrew
>>
>> -- 
>> 	*Andrew DeMerchant*
>> *Computer Technologist*
>> ph.1-877-2GEMTEC x.163
>> fax 506-453-9470
>>
>> /GEMTEC Limited <http://www.gemtec.ca>
>> /191 Doak Road
>> Fredericton, NB, Canada
>> E3C 2E6
>>
>> ------------------------------------------------------------------------
>>
>> _______________________________________________
>> mapguide-users mailing list
>> mapguide-users at lists.osgeo.org
>> http://lists.osgeo.org/mailman/listinfo/mapguide-users
>>   
> ------------------------------------------------------------------------
>
> _______________________________________________
> mapguide-users mailing list
> mapguide-users at lists.osgeo.org
> http://lists.osgeo.org/mailman/listinfo/mapguide-users
>   

-- 
	*Andrew DeMerchant*
*Computer Technologist*
ph.1-877-2GEMTEC x.163
fax 506-453-9470

/GEMTEC Limited <http://www.gemtec.ca>
/191 Doak Road
Fredericton, NB, Canada
E3C 2E6

-------------- next part --------------
Skipped content of type multipart/related


More information about the mapguide-users mailing list