Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Chinese

Pagetitle
安全最佳实践
安全最佳实践

Table of Contents

How to check Security Issues?

Image Added

Steps
  1. Log in as an administrator
  2. Open up the Administrator Bar
  3. Click on Monitor
  4. Click on Governance Health Check
  5. Check Category: Security 

SSL

English
Enabling SSL would ensure that communication between the end user's browser to be server is secure. Please see Setting Up SSL on Tomcat to learn more.
Chinese

启用SSL将确保最终用户的浏览器与服务器之间的通信是安全的。请参阅  在Tomcat  上设置SSL以了解更多信息。

...

Thai

ใช้คุณสมบัตินี้ภายใต้ Map Participants to Users ผู้เข้าร่วมกับผู้ใช้เพื่อจำกัดผู้ที่สามารถเริ่มต้นกระบวนการ

...

UI Menu Permission Control

Chinese

用户视图菜单权限控制

Permission Control is used to exert control and manage access to various components in a developed Joget App. There are 4 main components/areas where permission control can be exerted. They are:-

...

Chinese

权限控制  用于在开发的Joget应用程序中对各种组件进行控制和管理访问。有4个主要组件/区域可以进行权限控制。他们是:-

  • UserviewUI

    Chinese

    用户视图

  • Userview UI Category

    Chinese

    Userview类别UI类别

  • Form

    Chinese

    表单

  • Form Section

    Chinese

    表单分区

Info
titleShowing the App in App Center only after user is logged on

The most common practice is to list down apps in the App Center only if the user is logged in. To do so, head to the UI PropertiesSettings of your app, and locate Permission Type and set it to Logged In User.

Chinese

最常见的做法是仅在用户登录时在App Center中列出应用程序。为此,请到 您的应用程序的“用户视图属性 ”,然后找到“ 权限类型” 并将其设置为“ 登录用户”

Thai

แนวทางปฏิบัติที่พบบ่อยที่สุดคือการแสดงรายการแอพใน App Center เฉพาะเมื่อผู้ใช้ลงชื่อเข้าใช้ โดยให้ไปที่ Userview UI Properties ของแอปของคุณจากนั้นค้นหาประเภทการอนุญาตแล้วตั้งเป็น Logged In User


As a best practice, the userview UI should be secure by default. You can set the userview UI permission as a whole to "Logged In User" before further hardening at each and every userview UI category, including the hidden ones. An unprotected userview UI allows anonymous users and even robots (i.e googlebots to cache the page) access the userview UI when the app is set to published.

"Hide From Menu" under Userview UI Category does not mean it is not accessible. It is simply not visible to users.

...