how i tie confidence hybrid asp.net 1.1 / ajax solution?
scenario
i have an html/javascript website uses javascriptsoapclient promulgate an asp.net 1.1 web use method read/write sql database. (). database contains opposite demographic information--no names, credit cards, addresses. radically information collected information mining purposes.
the site live, nonetheless wish broach some-more secure communication between javascript/ajax fan wbe use both destiny projects. operative contractors financial industry, during indicate we're going nailed question: website hackable? don't have fortitude out the ears.
i am already following best practices such communicating database around management parameters stored procedures). however, now anyone crop the web use outline figure out devour the unprotected services.
questions
- with hybrid fortitude (i.e. end-to-end microsoft) should i authenticating fan requests web service?
- if i start flitting username/password identifiable component web use authentication, should i concerned pivotal generated/stored fan side?
Comments
Post a Comment