
58
Setting
Default
Recommendation
Description
Disable access to
internal ColdFusion
Java components
Unchecked
Checked
The internal ColdFusion Java
components may allow
administrative duties to be
performed.
Some developers may write code
that relies on these components.
This practice should be avoided as
these components are not
documented.
Prefix serialized
JSON with
Unchecked: //
Checked: //
This setting helps prevent JSON
hijacking, and should be turned on.
ColdFusion AJAX tags and functions
automatically remove the prefix.
If developers have written CFC
functions with returnformat=”json” or
use the SerializeJSON function, the
prefix will be applied, and should be
removed in the client code before
processing.
Developers can override this setting
at the application level.
Maximum Output
Buffer size
1024KB
Lower
A lower output buffer size may
reduce the memory footprint in some
applications.
Summary of Contents for 38043740 - ColdFusion Standard - Mac
Page 5: ...5 ...
Page 12: ...12 Next Click Add Roles and select the checkbox next to Web Server IIS ...
Page 26: ...26 ...
Page 33: ...33 ...
Page 38: ...38 ...