postback security


i've operative jquery *.asmx web services lately, i'm perplexing security-conscious doing so.



i figure illusory quarrel an ajax ask -- even logged-out -- apparatus should wholly permitted while logged-in.



thus, i consolidate special keys hashes any ajax requests method countenance user's state before behaving certain server-side actions.



however



i always feigned postbacks stable regard. .net pitch an blunder viewed ask tampered with.



is stable assumption? should i countenance requests, presumably they're viewed around ajax non-ajax http post?



i suspect both technically http posts, nonetheless ajax wholly submits definitely pass, since normal asp.net includes viewstate values. correct?



Comments

Popular posts from this blog

why does floated <input> control floated component slip over too distant right ie7, nonetheless firefox?

grails record upload problems

unable interpret unicode character