Hi all, At Aston we publish our student timetables using Celcat Web Publisher and use the timetable redirector feature so that we can have a direct link in our student portal that downloads a pdf of the timetable. While it works fine, this is a security concern because in theory any web user can view any student's timetable just by changing the unique Id and knowing the right url syntax. The timetables reside in an IIS web folder and there is no read restrictions on it because student's need to be able to download their timetable from wherever they are logged into our portal. I just wondered if anyone else has experienced this sort of issue using Web Publisher and could provide some advice on how to improve security? |