10 FileMaker Pro Web Publishing Security Guidelines
Here is a partial list of script steps that may cause problems when used with web published
databases:
Edit
Delete
Show Omitted
Open
Close
Set Multi User
Delete all
Replace
Send Mail
Quit
Note
The Web Security Database can be used to disable specific web users from running any
scripts in a database, but cannot be used to selectively allow specific scripts to be executed.
3.
It is recommended that you assign Edit and Delete privileges to web only passwords only if they
are necessary. See Recommendations on page 22 and Web Security Database tips on page 41
for more information.
4.
Use access privileges as the recommended method of applying security for Instant Web
Publishing, and configure record by record security, if additional security is necessary. See
Protecting data for Instant Web Publishing on page 17 for more information.
Note
If a password limits browse privileges but does not limit the privilege to delete records, it is
possible for users to delete records they cannot view. If FileMaker Pro detects this situation, it will
display an alert when you create the password, but it will not prevent you from creating the
password.
Important
When you use access privileges as the only means of securing your database, any valid
password is potentially available for use when guests access your database over the Web/intranet.
The Web Companion permits you to enter any password defined in your database. If someone is
aware of a valid password, they can enter that password through a browser's password dialog box.
This includes master passwords, which provide access to the entire file. Even if you define unique
passwords for web only users, there is no way to disable your master password(s). Make sure that
any master passwords you define are difficult to guess and are known only to those who need to
use them. As FileMaker Pro access privileges are the only means of providing security through
Instant Web Publishing, you should use Custom Web Publishing and the Web Security Database if
you require a different level of security.
For more information about FileMaker Pro access privileges, see the
FileMaker Pro User's Guide
and the FileMaker Pro online Help.