How can i prevent anonymous user to run domino java servlets

Viewed 69

How can i prevent anonymous users to run domino servlet in a database. I have set the access for Anonymous to no access and then it works find ... but ...

We need to have the Anonymous access set to "NoAccess" and "Read public documents" in the Access Control list. I don't understand why anonymous users are allowed to run the java servlet when we have "read public document" checked.

Can I prevent this in some way? we don´t wanne allow the Anonymous to run servlets. In our databas we have an login form thats allow public acess. Is this possible or do we need to do this in another way?

1 Answers

If Anonymous is granted Read Public in the ACL, the anonymous users have to be given the ability to access design elements. That includes forms, views, and I guess servlets, too. That would explain why it behaves as you have observed.

For a workaround, you could consider putting the servlet in a separate NSF file where you can set the ACL so that Anonymous has "No Access" without the "Read public documents" flag? This might require a small amount of reprogramming if the Java code is assuming that it is accessing the current database, but the change could just be a single line of code and it should lock your servlet down.

Related