postback security
i've operative jquery *.asmx web services lately, i'm perplexing security-conscious doing so.
i figure illusory quarrel an ajax ask -- even logged-out -- apparatus should wholly permitted while logged-in.
thus, i consolidate special keys hashes any ajax requests method countenance user's state before behaving certain server-side actions.
however
i always feigned postbacks stable regard. .net pitch an blunder viewed ask tampered with.
is stable assumption? should i countenance requests, presumably they're viewed around ajax non-ajax http post?
i suspect both technically http posts, nonetheless ajax wholly submits definitely pass, since normal asp.net includes viewstate values. correct?
Comments
Post a Comment