<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication without REST in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/authentication-without-rest/m-p/51472#M30054</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;But how to prevent not authorized users from starting instances and how to prevent completeing of tasks by 'guerilla-users'?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;Might not what you want to hear, but the basic answer is: by implementing this. Just build a ui where they only get to see tasks that belong to them, cannot change id's to get to other tasks etc… Basically like you would secure any other webapp with shared data.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Jul 2011 13:22:44 GMT</pubDate>
    <dc:creator>ronald_van_kuij</dc:creator>
    <dc:date>2011-07-15T13:22:44Z</dc:date>
    <item>
      <title>Authentication without REST</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/authentication-without-rest/m-p/51471#M30053</link>
      <description>Hi,Using the REST-API, the user has to login to do any action on the engine. As I have seen, no authentication/authorisation at all is needed when using the Java-API directly. I'd like to achieve the following goals&lt;IMG id="smileysurprised" class="emoticon emoticon-smileysurprised" src="https://migration33.stage.lithium.com/i/smilies/16x16_smiley-surprised.png" alt="Smiley Surprised" title="Smiley Surprised" /&gt;nly existing users can start process instances an the userId is stored in START_USE</description>
      <pubDate>Fri, 15 Jul 2011 12:26:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/authentication-without-rest/m-p/51471#M30053</guid>
      <dc:creator>gant</dc:creator>
      <dc:date>2011-07-15T12:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication without REST</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/authentication-without-rest/m-p/51472#M30054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;But how to prevent not authorized users from starting instances and how to prevent completeing of tasks by 'guerilla-users'?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;Might not what you want to hear, but the basic answer is: by implementing this. Just build a ui where they only get to see tasks that belong to them, cannot change id's to get to other tasks etc… Basically like you would secure any other webapp with shared data.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 13:22:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/authentication-without-rest/m-p/51472#M30054</guid>
      <dc:creator>ronald_van_kuij</dc:creator>
      <dc:date>2011-07-15T13:22:44Z</dc:date>
    </item>
  </channel>
</rss>

