Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

07_11_2011 #46

Closed
haoqili opened this issue Jul 11, 2011 · 1 comment
Closed

07_11_2011 #46

haoqili opened this issue Jul 11, 2011 · 1 comment

Comments

@haoqili
Copy link
Owner

haoqili commented Jul 11, 2011

TODO:

  • ask Michael what to do with CSP
    --> allow eval for setInterval?
    --> allow inline?
    --> make our own to get around setInterval?
    --> make our own to get around in-body script?

  • start on Access Control

    ACCESS CONTROL
    Presentation, Business, Data Layer Access Control
        Presentation and Data layers use decorators
        Read about presentation layer protection 
    (Possible) Two tier design for admin account separation
        The picture of separate control of changing passwords 
    

  • 24 start to separate richtext and url

  • 7 HTTP Only fix

  • 16 SQL injection can't include script

DONE:

@haoqili
Copy link
Owner Author

haoqili commented Jul 11, 2011

#43 <-- --> #48

@haoqili haoqili closed this as completed Jul 12, 2011
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant