'Sensible' Definition & Security settings for a Production APEX environment

Hi Folks.
What's the feeling on Definition and Security settings for a production APEX application?
Here are my settings for my UAT environment (not quite in production just yet)
Debugging: NO
Status: AVAILABLE
Build Status: RUN APPLICATION ONLY
Authorization Scheme : MUST NOT BE PUBLIC USER
Session State Protection: ENABLED
In the APEX Administration setup, access to my site is restricted by IP also. As a consequence I think it's buttoned down quite tightly but, eventually, we plan to open this up to the Big Bad Web!!
What are your thoughts on the pro's and con's, the why's and wherefore's of one setting or another.
I'm hoping this thread will prove to be a good forum for discussing APEX application security configurations and a reference for others.
Please feel free to link to whitepapers of relevance.
Maybe someone could take up the challenge of producing an 'UNHACKABLE' :-) APEX website?
Simon.

Hi Simon,
If you're just talking about instance settings, then you might also add to that using the 3.1 runtime only instance.
If we're opening it up to application design, well...that's a whole other matter ;)
John.
http://jes.blogs.shellprompt.net
http://www.apex-evangelists.com

Similar Messages

  • Java WebDynpro's and IE security settings for file download

    We have a EP 7.0 SP13 environment on which we have deployed a number of own developed java webdynpro's. In some of these webdynpro's we provide the file download functionality. The portal and webdynpro's are used by both internal personnel and external customers.
    On the other hand the default Internet security settings for Internet Explorer, disable "Automatic prompting for file downloads".
    When a user, with these default security settings active, tries to use our webdynpro's file download functionality, the screen seems to refreshes but no file download starts. When (s)he retries, the session runs for some minutes and gives following error message:
    "com.sap.tc.webdynpro.services.session.LockException: Thread SAPEngine_Application_Thread[impl:3]_20 failed to acquire exclusive lock on client session ClientSession".
    This behavior is explained in SAPNote 1234847. Webdynpro provides a single-thread module, meaning a user session is blocked for the during of the request. And because the previous file download isn't yet completed the new try can't start.
    Issue now, although the users IE settings allow file downloads and don't block pop up's, he can't download the file and even isn't made aware of the cause of the failure.
    How can we avoid this issue, without having to communicate the
    application requires specific browser settings?

    Welcome to the Apple Support Communities
    See > http://support.apple.com/kb/HT5290
    You can install the program using different ways:
    1. Right-click the application installer and choose Open.
    2. Go to System Preferences > Security and Privacy and select Anywhere in Allow applications downloaded from

  • Query security settings for users

    Hi again.
    I'm looking for a way of querying security settings for a user.
    ie I understand that company/division etc security is implemented through responsibilities.
    In which case, is there a way to retrieve those exclusions per user?
    (eg User 1 cant see company 50)
    Thanks,
    g.

    Hi again.
    I'm looking for a way of querying security settings for a user.
    ie I understand that company/division etc security is implemented through responsibilities.
    In which case, is there a way to retrieve those exclusions per user?
    (eg User 1 cant see company 50)
    Thanks,
    g.

  • How to provide security settings for the adobe form using livecycleDesigner

    Hello,
    I am very new to form designing,
    can any one please tell me how to provide security settings for the adobe forms at client side?
    Regards,
    Menaka

    Hi,
    that is a good topic for the ADFS forum.
    ADFS forum - http://social.msdn.microsoft.com/Forums/vstudio/en-US/home?forum=Geneva
    But you could pass the user-agent as incoming claim type Client User agent. User-agents can be manipulated, so if that is an issue you can look into Device Registration and the Device OS type from there. That is also a incoming claim but requires DRS and
    DRS is not available for all plattforms.
    Hth,
    Lutz

  • WRT54GP2 security settings for HP Ipaq 111 handheld

    I have a home wireless network, using a Linksys WRT54GP2 wireless router. I'm trying to secure the network, with has 3 wireless systems, my home PC, a notebook, and my Ipaq 111. I can get my home PC and the notebook to work when I setup the WRT54GP2 router using Authentication: WPA-Pre-Shared Key and Data Encryption: TKIP, but the Ipaq 111 will not even see the router with any security setting. When the security settings for the Linksys Wireless Router WRT54GP2 are disabled the Ipaq 111 sees the router and connects to the internet.
    The HP Ipaq 111 handheld has the following security options: Authentication: Open, Shared, WPA, WPA-PSK, WPA2, WPA2-PSK. Data Encryption: Disabled, WEP, TKIP, AES.
    Does anyone have any ideas of how to get the Ipaq 111 to work on the secured Linksys WRT54GP2 router?
    Thanks for any help.
    John

    On your Router setup page, Click on the Wireless tab and below change the Wireless Channel to 11-2.462GHz and click on Save Settings, then click on the Sub tab Advanced Wireless Settings and below Change the Beacon Interval to 75,Change the Fragmentation Threshold to 2304,Change the RTS Threshold to 2304 and Click on Save Settings...
    Now see if you can locate your Wireless Network and attempt to connect to it on your Ipaq.

  • WRT54GP2 security settings for a HP Ipaq 111 handheld

    I have a home wireless network, using a Linksys WRT54GP2 wireless router. I'm trying to secure the network, with has 3 wireless systems, my home PC, a notebook, and my Ipaq 111. I can get my home PC and the notebook to work when I setup the WRT54GP2 router using Authentication: WPA-Pre-Shared Key and Data Encryption: TKIP, but the Ipaq 111 will not even see the router with any security setting. When the security settings for the Linksys Wireless Router WRT54GP2 are disabled the Ipaq 111 sees the router and connects to the internet.
    The HP Ipaq 111 handheld has the following security options: Authentication: Open, Shared, WPA, WPA-PSK, WPA2, WPA2-PSK. Data Encryption: Disabled, WEP, TKIP, AES.
    Does anyone have any ideas of how to get the Ipaq 111 to work on the secured Linksys WRT54GP2 router?
    Thanks for any help.
    John

    What is the model no of the Wireless Adapter you are using on the HP laptop...?
    Have you tried updating the driver for the adapter...?
    Try to adjust the wireless settings on the router...Open the setup page and  Under the Wireless tab,Change the Network Mode to mixed...Keep the Wireless Channel on 11-2.467GHz and click on save settings...Under the Advanced Wireless Settings, Change the Beacon Interval to 50,Change the Fragmentation Threshold to 2304,Change the RTS Threshold to 2304 and Click on Save Settings...

  • Security Settings for more

    I saw this on a site that has many users in Iran
    This setting does not harm anyone to use and useful
    Or not.
    Security Settings for more I With a simple trick for the Firefox browser you can always Certificate of forged and stolen check in Amman Even if all the fake certificate to get It is mentioned in the ability of the default browser is Chrome
    [IMG]http://i56.tinypic.com/2hxp0jo.jpg[/IMG]
    (My choice when ocsp server connection fails, treat the certificate az invalid The chrome is not activated in your browser, you can enable this option, none of the sites Sites such as the bank's internal pull Vardsh Nmytvnyd) Message to your browser if the connection is untrusted or ocsp error gave me a few times to retry This message was repeated again Mlvmh Jlyh site certificate Gmail did not do anything and sit in. I think what Yahoo's Site of the National Bank The fake site, your freedom The main site of your freedom
    2. Firefox and Chrome browsers, by default the system uses rc4 128 bit encodings The system according to security experts, is one of the weakest systems encodings I will use it only for high speed One of the reasons that the wep hack wireless internet use Hmynh But unlike wireless Internet connections that use wpa2 aes encodings system In theory you could perform any For more information, read this article I did not find any option in Chrome that I can disable this feature To disable this option in the Firefox browser, do the following operation about: config Type I rc4 All of the following options to make false Tqyyr
    [IMG]http://i51.tinypic.com/mbr51i.jpg[/IMG]

    Check the file /etc/pam.d/sshd and /etc/pam.d/login.
    Adjust the entry auth required pam_tally2.so deny=5 onerr=fail, as needed.
    Modify deny= to the number of allowed failed attempts.
    Refer to Mos Note 1269133.1 for details.

  • No Global security settings for my localhost, Help?

    Player 9
    I develop flash apps in localhost and I receive that error
    message:
    Adobe Flash Player has stopped a potential unsafe operation
    The following local application on your computer or network:
    /Application/MAMP/htdocs/joomlagraf/modules/.../ssp.swf is
    trying to communicate with this Internet-enabled location:
    localhost
    I beleive you can fix that in the Global security settings,
    but this panel is absent when I right click on my flash movie. I
    got —> Privacy/Local Storage/Microphone/Camera only, on a
    fresh player 9 install.
    How can I access that Global security settings panel, what
    can I do???????????
    My work is stopped......... Help!

    Hi Popocatepelt,
    Glad to hear that worked for you….
    Local Access Only allows the published SWF file to interact
    with files on the local system, but not on the network. Access
    Network Only lets the published SWF file interact with files and
    resources on the network, but not on the local system.
    For more info take a look at the following
    http://www.adobe.com/products/flashplayer/security/
    For local content:
    http://www.adobe.com/products/flashplayer/articles/localcontent/

  • Allowing Global Security Settings for Local Flash Content

    Hi all,
    We have developed one e-learning course for our client. This
    course will be deployed on the CD; that means it will run locally.
    This CD will be dstributed to thousands of users. In this scenario
    I am currently suffering from the Global Security Settings issue as
    this project uses Fscommand to communicate with the javascript. We
    can set the Global Security mannually but it is not feasible to ask
    client to mannaully set the Security Settings to "always" as there
    are thousands of users viewing this course locally.
    I have tried setting "always" value to allowScriptAccess
    property of the Object/embed tag in the html but it does not work
    where the browser Security Settings are kept as "High".(I think
    this is the reason)
    So what will be the workaround for this issue?
    Please reply me if you gone through this problem and found
    any workaround.
    Thanks in advance.

    Hi Popocatepelt,
    Glad to hear that worked for you….
    Local Access Only allows the published SWF file to interact
    with files on the local system, but not on the network. Access
    Network Only lets the published SWF file interact with files and
    resources on the network, but not on the local system.
    For more info take a look at the following
    http://www.adobe.com/products/flashplayer/security/
    For local content:
    http://www.adobe.com/products/flashplayer/articles/localcontent/

  • How to fix Security settings for Startup folder on startup

    Hello.
    i am getting the message that the security settings have changed. and due that items in my start up folder has been disabled. ( now that has not stopped me from working but it is annoying in the beginning) Now when I hit the question mark it tells you about it and the solution, it talks about have MacOsX fix it , but it does not show how On other posts it says that i would receive that option on startup but nothing there either. So How can i fix it .

    racb wrote:
    i took all the folders out and restarted and the same message came up that the startupitems folder is insecure and a second message saying that folder DS_Store in the startupitems folder is disabled because of insecure settings. Now I can not see that folder in the startup items folder, any idea
    Probably just as it says, DS_Store is corrupt. This stores the settings for a folder.
    To see if we can find the invisible folder and remove it open Terminal in your Utilities folder and at the prompt copy and paste defaults write com.apple.finder AppleShowAllFiles True; killall Finder
    If you can see the file now just delete it.
    Then, switch back to visibles only and create a new folder called Startup Items.
    defaults write com.apple.finder AppleShowAllFiles False; killall Finder
    Or, simply creating a new Startup Items folder may be enough.
    -mj

  • Help w/ Security Settings for Mobile Hotspot w/ 2.2

    I posted this over on moto's forum yesterday, but so far I've gotten no response. I figured I go ahead & post it here also, to see if some(1) may be able to help me w/ it:
    I've searched far & wide, & haven't been able to come up w/ an answer to this. I would very much appreciate any info, advice, or education on this.
    When I travel, I use the X to connect my laptop (HP notebook w/ Vista home prem) to the net, thru the hotspot. I've only been able to connect thru the hotspot using the WEP security setting. Since updtg. to (2.2), still can only connect using WEP setting. Now the only post I've been able to find w/ anything @ all about the hotspot & the security settings, was just a post about the steps to initially set it up. That was here on this forum & there were screen shots of pages frm the vzw site that (1) of the vzw employees had posted to answer that question. It showed WAP - 2 being used.
    Now frm what I've read & understand, from searching for info on the diff. between the (2) settings, is that WAP / WAP - 2 is a much more secure setting than WEP. Also, I try to read-up on this kind of stuff to learn it, however, I'm still doing just that, learning & don't completely understand the diff. frm a tech. standpnt. I do sometimes do banking & paying bills online while traveling, so this is a major concern for me.
    Is the diff. between the security of the (2) settings enough to worry about, as far as the fact that I'm dealing w/ personal info? Obviously, I don't need somebody in next hotel rm., etc., being able to get into my connection & see my info on my laptop. Also, has any(1) had any luck connecting thru the hotspot w/ WAP or WAP - 2 on their laptop? If so, is the problem poss. settings on my laptop? Thank u in advance any help ya'll can offer.
    pcw67427

    Ahh, okay, P.C., I see what you are talking about.
    Network security is something that I've thrown myself into pretty heavily this year as we are more and more deploying networks within our audio and lighting systems for shows and concerts. In one instance, we have digital mixing consoles that can be controlled via that console's editing software running on a PC (or Mac, if you will). There are times where, instead of having the typical huge mixing console, 3 or 4 racks of power supplies, processing and effects units, and other supplies, I have a nice, comfortable chair and my X200 tablet PC mixing the entire show. I use the basic Linksys router connected to my Gateway notebook, the console, or consoles, and the speaker systems' processors. Then I use the X200 and Remote Desktop to, well, remotely control all of that.  One of my purchases later this year will be a real enterprise router, hopefully for more range and speed.
    Naturally, it would suck to no end if someone were to hack into my WLAN network, thinking they were logging onto someone's network to steal some internet time. The havoc that this could cause could potentially be a show-stopper. Or in extreme cases, cause some damage from accidental overdriving something. 
    Unfortunately, I've only been able to learn some very basic things because of my work load, shows, and just time in general. But I have learned that WEP is fairly easy to crack, while WPA is much, much harder, and WPA-2 being even more secure. What I would learn to know is WHY this is the case. I have enabled the WPA-2 security features in all of my routers. I also use the MAC address filters, although, yes, MAC addresses can be spoofed without too much trouble. But it's another layer of protection.
    As I mentioned in the PM, I plan to enable the hotspot feature on my account this week and play with the X's hotspot capability during our upcoming state fair. I'll be looking at the security settings pretty closely since I know how those road guys are (since I AM one, LOL), constantly hunting for a connection to log onto, LOL.
    As I said, I'm woefully lacking in thorough knowledge about network security. I'll bet there are some real wizs (wizi?) around here that can be more help than I can. I have heard a couple of IT guys say that they never, ever do banking and financial business on ANY wifi connection, regardless of the security method used. One of these guys has said that he'd rather do banking over a good 3G connection that he would any kind of WLAN. Whether there's anything one way or the other to these claims, I simply don't know, but I'd love to find out.
    One thing is for certain...Hotels are FULL of folks hunting for internet connections and logging onto anything they can, err, get their hands on. So it goes without saying that you need better encryption than WEP if you plan to do financial stuff online. I haven't looked, but can you turn off the SSID on the X's hotspot feature? That would at least, not tell the world about the network you have, LOL
    Hopefully, I'll learn some more next week. In the meantime, I hope some IT types can comment on this subject, And thanx in advance,
    Take care, 
    Geri O

  • Email server security settings for Thunderbird

    Hi - my first message to the Forum so hope I am in the right section. I'm on Windows 8. My email is working fine via an email client (Thunderbird). However, the server security settings suggested by BT instructions for T/Bird seem very weak to me............. - Connection security - none - Authentication method - password, transmitted insecurely. Can anyone using Thunderbird please advise me what they should be please. Help would be appreciated - thank you. John
    Solved!
    Go to Solution.

    Am I OK shifting the incoming to IMAP from POP3 please ?
    John
    Your choice, they are 2 completely different ways of operating e-mail. With IMAP, the mail is held on the server and can be accessed from multiple devices, POP3 downloads the mail to the client and is deleted from the server (unless specifically told to leave a copy on the server) BT don't advertise the fact but does in fact support secure POP3. the server mail.btinternet.com supports POP3 using SSL on port 995 and secure SMTP on port 465

  • NotAllowedError: Security settings for template.spawn()

    I'm creating a PDF document that heavily uses the template.spawn() method. My understanding is that the spawn() method is allowed whenever the PDF document is given "Reader Rights" in Acrobat. I am using Acrobat X (and Acrobat Forms, not LiveCycle) and have saved my PDF with Reader Extended Rights. When I load the file in Reader 11 and click the button that spawns pages, I get the javascript error: NotAllowedError: Security settings prevent access to this property or method. Am I doing something wrong or have I misunderstood the notation in the Adobe API that says .spawn() is allowed with Reader Form Rights?
    Thanks,
    John

    Hi John,
    All the changes from version to version sure make things confusing.  When Adobe Reader XI was released it came with some new features that DO NOT require Rights and those include the ability to Spawn Templates as well as Fill and Save data in PDF forms ( not LiveCycle though, just to add more confusion).  So first, you don't need to add Rights to your PDF at all unless you require some other Right that is not availalbe free in Adobe Reader XI.  Given that, ALL of your users will need to use Adobe Reader XI or Acrobat since earlier versions of Reader do not include the Spawn Templates without Rights.  And, if you want Spawn Templates to work in an earlier version of Adobe Reader, that is one of those that required the expensive LiveCycle Reader Extension server product, not one built into Acrobat.
    When you do apply rights to a PDF those Rights block all functionality not explicitly granted by the Right.  Since Spawn is there already your applying Rights negates it- kinda wierd but pretty sure that's why you get the error.
    The Spawn Templates is such a great new addition to Reader though, isn't it?
    Hope this helps,
    Dimitri
    WindJack Solutions
    www.pdfscripting.com
    www.windjack.com

  • Update security settings for adobe flash player

    I have windows 7, 64bit, adobe flash player 11. 
    Can't play You Tube videos...message say need to update flash player.
    Went to adobe site....tried to download latest version 11.8, and message says I need to update security settings to allow.
    I'm a beginner...where and how to update these settings.

    Download the Adobe Flash Player installer directly by right clicking one of the following links.
    Flash Player for ActiveX (Internet Explorer)
    Flash Player Plug-in (All other browsers)
    Save the installer - DO NOT run it yet.
    Reboot your system.
    BEFORE you open anything else, locate and run the installer you downloaded.

  • MacBook security settings for Firefox3 ?

    Firefox 3 is so slow to load some pages and refuses to load others that Safari does instantly almost. I had no problem with FF2 at all and preferred it to Safari. I have been told to check the security settings as these could be a possible answer but am not sure what I am meant to be looking for ? The firewall is on, as it always is and file sharing is off....anything else to look at ?
    Thanks
    4jbl7

    fwiw i ditched ff3 and reverted to ff2 due to various problems
    unless you have a need for some exta feature in ff3 i'd suggest switch back to ff2 until ff3 matures a bit more

Maybe you are looking for

  • In veiwing streaming video picture stalls in full screen

    just recently when playing streaming videos the picture is stalling in full screen mode, but resumes when you move the mouse, but will do the same in a moment or two, streaming works good in regular mode, i dowmloaded newest version of flash player,

  • Standard function MapwithDefault in NWDS?

    Hi Folks, Do we have any standard function available in NWDS for achieving the MapwithDefault mapping. FYI, I am trying to propagate the tag of the field for no input value in the source.

  • Too much Delay

    Hi all, I have a 4503 and some 4006s with WS-X4548-GB-RJ45 modules. I these switches I have servers connected via 1000BaseTX to the modules. The problem is that when I make backups (Gigas of info), the delay it takes is worrying and frustrating (it t

  • Cash Flow Configuration (Urgent)

    Hi Please tell me the  details about cash flow configuration. good answers will be rewarded with points

  • Sun application server 9 and jndi

    I have just started to learn to use EJB and am trying to deploy my first app. I have created a simple stateless bean and am trying to call it from a servlet which I have also deployed. This is the code I am using to try and obtain the bean from the s