Welcome To The Home Of The Visual FoxPro Experts  
home. signup. forum. archives. search. google. articles. downloads. faq. members. weblogs. file info. rss.
 From: Jun Tangunan
  Where is Jun Tangunan?
 Cabanatuan
 Philippines
 Jun Tangunan
 To: David Mustakim
  Where is David Mustakim?
 Jakarta
 Indonesia
 David Mustakim
 Tags
Subject: RE: apply active directory to a menu system
Thread ID: 393609 Message ID: 393746 # Views: 38 # Ratings: 0
Version: Visual FoxPro 6 Category: Active Directory
Date: Monday, December 23, 2013 1:21:25 AM         
   


> >
> >
> > I read some exchanges above (not all) and this is what your client wants to achieve: Use the Server's AD in authentication instead of another separate login form for your VFP app.
> >
> > If so, then the solution is very simple. Just remove your log in form. When they click, send them straight to main menu/form.
> >
> > You see, another login form aside from what the OS is using is for their additional protection. But if they want it that way (no more login form for your app), then that is their decision and risk.
> >
> > All you need to do then is share your app's folder in the server for specific users. So if they log in on the OS on your local domain, then those users granted permission can access it. If they log in locally, they can't even connect to that folder. And that sharing is better done manually, not through codes tampering with server.
> >
> >
> >
> >
> >
> >
> > https://vfpx.codeplex.com/releases/view/99045
> > http://sandstorm36.blogspot.com
>
> I mentioned "BB's impersonation earlier", here is more about it:
> https://www.foxite.com/faq/default.aspx?id=48
>
> .


I know, I am the one who rated that earlier, LOL!

But then again, why the need for impersonation in this case? It is just duplicating what the server OS is already doing which is blocking unwanted users.

Like I said above, share the folder to be accessed only by specific users in the AD list on the server itself. When those users successfully logs in on the local unit via the local domain, then they are valid users meaning they know the username and password given to them by their IT Admins.

If not, they won't be able to log in on the OS on that domain. Alternately, some users can log in locally (on the local unit itself) but since it does not pass authentication on the server, then they cannot also access that shared folder. Unless an IT admin can grant them "extra" access by connecting that local user onto that shared folder in the server using an AD's admin account and keeping it alive so it won't have to request for that admin access from time to time when needed.

True, that protection by AD is enough to disallow unwanted users to our app. However, I am not fully comfortable with that approach as users are tend to be careless and lazy. Sometimes they will suddenly leave their chair without logging of or simply pressing Winkey + L. Most of the times, they may stand up for a smoke (this reminds me of someone aside from myself but cannot remember who, his name is on the tip of my tongue, LOL), a chitchat, a cup of coffee, or to relieve themselves of extra fluids. And that additional login form aside from OS login authentication adds extra protection to the app.

Otherwise, with what the client needs, when user leaves his desktop on, then anyone can sneak in to access it.

Sometimes, we should not simply follow what the client wants out of lack of understanding. I have contradicted several clients' desires in the past by explaining to them the pros and cons and most of the time after they understood and saw the scenarios I painted for them, they back out of some ridiculous requests. ;-)




https://vfpx.codeplex.com/releases/view/99045
http://sandstorm36.blogspot.com

ENTIRE THREAD

apply active directory to a menu system Posted by DEREK DODOO @ 12/20/2013 4:00:04 PM
RE: apply active directory to a menu system Posted by Koen Piller @ 12/20/2013 4:12:52 PM
RE: apply active directory to a menu system Posted by Pete Sass @ 12/20/2013 7:04:25 PM
RE: apply active directory to a menu system Posted by DEREK DODOO @ 12/20/2013 7:26:19 PM
RE: apply active directory to a menu system Posted by David Mustakim @ 12/20/2013 8:15:32 PM
RE: apply active directory to a menu system Posted by Pete Sass @ 12/20/2013 11:31:54 PM
RE: apply active directory to a menu system Posted by DEREK DODOO @ 12/21/2013 10:50:20 AM
RE: apply active directory to a menu system Posted by Pete Sass @ 12/21/2013 3:04:58 PM
RE: apply active directory to a menu system Posted by David Mustakim @ 12/22/2013 12:03:21 AM
RE: apply active directory to a menu system Posted by Anders Altberg @ 12/21/2013 12:42:10 AM
RE: apply active directory to a menu system Posted by Koen Piller @ 12/21/2013 9:47:22 AM
RE: apply active directory to a menu system Posted by DEREK DODOO @ 12/21/2013 10:34:03 AM
RE: apply active directory to a menu system Posted by Koen Piller @ 12/21/2013 4:06:02 PM
RE: apply active directory to a menu system Posted by David Mustakim @ 12/22/2013 12:00:56 AM
RE: apply active directory to a menu system Posted by Koen Piller @ 12/22/2013 11:37:50 PM
RE: apply active directory to a menu system Posted by David Mustakim @ 12/23/2013 12:07:17 AM
RE: apply active directory to a menu system Posted by Jun Tangunan @ 12/23/2013 12:47:08 AM
RE: apply active directory to a menu system Posted by David Mustakim @ 12/23/2013 1:06:19 AM
RE: apply active directory to a menu system Posted by Jun Tangunan @ 12/23/2013 1:21:25 AM
RE: apply active directory to a menu system Posted by David Mustakim @ 12/23/2013 2:46:15 AM
RE: apply active directory to a menu system Posted by Jun Tangunan @ 12/23/2013 5:18:30 AM
RE: apply active directory to a menu system Posted by David Mustakim @ 12/23/2013 5:41:04 AM
RE: apply active directory to a menu system Posted by Jun Tangunan @ 12/23/2013 6:56:01 AM
RE: apply active directory to a menu system Posted by David Mustakim @ 12/23/2013 3:02:13 PM
RE: apply active directory to a menu system Posted by DEREK DODOO @ 12/26/2013 9:44:56 PM
RE: apply active directory to a menu system Posted by DEREK DODOO @ 12/26/2013 9:46:27 PM
RE: apply active directory to a menu system Posted by Jun Tangunan @ 12/26/2013 11:31:55 PM
RE: apply active directory to a menu system Posted by David Mustakim @ 12/27/2013 3:05:57 AM