345
CHAPTER 16
Securing Applications
ColdFusion MX has two major security features:
•
Sandbox security
(ColdFusion MX Enterprise) or
resource security
(ColdFusion MX Standard),
where security restricts access to specific resources, such as tags and files.
•
User security
, which depends on a user identity.
This chapter provides an overview of ColdFusion security. It briefly describes how you use the
ColdFusion MX Administrator to configure sandbox or resource security, and discusses
structuring an application to take advantage of this security. It explains in detail how to
implement user security in ColdFusion applications.
Other chapters discuss specific security issues as part of the context of their topics. For example,
the chapter on LDAP (Lightweight Directory Access Protocol) discusses secure access to LDAP
directories. Similarly, the section
Chapter 20, “Enhancing security with cfqueryparam,”
on page 435
describes a method for preventing inappropriate access to SQL databases. See the
Security entries in the Index for a complete listing of such sections.
For detailed information on using Administrator-controlled security features, see
Configuring and
Administering ColdFusion MX
.
This chapter does not discuss general or web server security concepts and issues in any detail. For
example, it does not discuss web server security management issues, such as enabling HTTPS
protocol support. For information on enabling web server security features, see your web server
documentation. Many books and other resources are available on web and application security.
Contents
ColdFusion security features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 346
About resource and sandbox security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 346
About user security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 348
Implementing user security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 358
Summary of Contents for COLDFUSION MX 61-DEVELOPING COLDFUSION MX
Page 1: ...Developing ColdFusion MX Applications...
Page 22: ...22 Contents...
Page 38: ......
Page 52: ...52 Chapter 2 Elements of CFML...
Page 162: ......
Page 218: ...218 Chapter 10 Writing and Calling User Defined Functions...
Page 250: ...250 Chapter 11 Building and Using ColdFusion Components...
Page 264: ...264 Chapter 12 Building Custom CFXAPI Tags...
Page 266: ......
Page 314: ...314 Chapter 14 Handling Errors...
Page 344: ...344 Chapter 15 Using Persistent Data and Locking...
Page 349: ...About user security 349...
Page 357: ...Security scenarios 357...
Page 370: ...370 Chapter 16 Securing Applications...
Page 388: ...388 Chapter 17 Developing Globalized Applications...
Page 408: ...408 Chapter 18 Debugging and Troubleshooting Applications...
Page 410: ......
Page 426: ...426 Chapter 19 Introduction to Databases and SQL...
Page 476: ...476 Chapter 22 Using Query of Queries...
Page 534: ...534 Chapter 24 Building a Search Interface...
Page 556: ...556 Chapter 25 Using Verity Search Expressions...
Page 558: ......
Page 582: ...582 Chapter 26 Retrieving and Formatting Data...
Page 668: ......
Page 734: ...734 Chapter 32 Using Web Services...
Page 760: ...760 Chapter 33 Integrating J2EE and Java Elements in CFML Applications...
Page 786: ...786 Chapter 34 Integrating COM and CORBA Objects in CFML Applications...
Page 788: ......