2 Replies Latest reply on Jun 20, 2002 6:36 AM by pedrow

    Unauthorized user can takeover principals from objects in po

    pedrow

      I'm not sure but I think

        • 1. Re: Unauthorized user can takeover principals from objects i
          pedrow

          Sorry by mistake I posted my previous topic before I finished it writing.

          OK, the issue is that if I have authorized user that calls some object and this object is created with this users principals, other not authorized user can obtain this
          object from pool with authorized users principals.

          I don't think this should be like this. In my opinion
          container should check each user roles before it takes
          object from pool.

          Does any of you have some expiriance with this case?

          p.

          • 2. Re: Unauthorized user can takeover principals from objects i
            pedrow

            Sorry I had party last night and I didn't sleep to much, of course I wanted to post this topis in Security forum
            ;-(

            p.