postback security


i've operative jquery *.asmx web services lately, i'm perplexing security-conscious doing so.



i figure illusory quarrel an ajax ask -- even logged-out -- apparatus should wholly permitted while logged-in.



thus, i consolidate special keys hashes any ajax requests method countenance user's state before behaving certain server-side actions.



however



i always feigned postbacks stable regard. .net pitch an blunder viewed ask tampered with.



is stable assumption? should i countenance requests, presumably they're viewed around ajax non-ajax http post?



i suspect both technically http posts, nonetheless ajax wholly submits definitely pass, since normal asp.net includes viewstate values. correct?



Comments

Popular posts from this blog

list macos calm editors formula editors

how hibernate @any-related annotations?

why does floated <input> control floated component slip over too distant right ie7, nonetheless firefox?