﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>InstantASP Community Forums / Old Forums / InstantKB.NET 1.x / Suggestions &amp; Requests  / Additional Security Features / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>InstantASP Community Forums</description><link>http://community.instantasp.co.uk/</link><webMaster>sales@instantasp.co.uk</webMaster><lastBuildDate>Mon, 01 Dec 2008 18:08:45 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>Dear Richard,&lt;/P&gt;&lt;P&gt;I am forwarding your message to our development department for consideration for inclusion in the functionality of a later version.  Thank you very much for your suggestion and please do contact me with any further ideas that come to mind.&lt;BR&gt;</description><pubDate>Mon, 02 May 2005 09:57:05 GMT</pubDate><dc:creator>Carlos Muniz</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>Hi Ryan,&lt;/P&gt;&lt;P&gt;Is it still the plan to embed attachments within the database for v2 and have them searchable?   That would certainly resolve a problem for me....  &lt;/P&gt;&lt;P&gt;Enhancement/Security requests:&lt;/P&gt;&lt;P&gt;1) Expire date on users&lt;/P&gt;&lt;P&gt;2) Logging of logins/outs  with IP address&lt;/P&gt;&lt;P&gt;3) Restrict userid to an IP address&lt;/P&gt;&lt;P&gt;4) Personal KB - only for me.  Ability to add/edit/view articles within this element and Promote them to the admin for general inclusion&lt;/P&gt;&lt;P&gt;5) Workflow on approval process.  Mark users as having contributor rights (to given categories if possible) so that they can submit articles to an admin who accepts, rejects or places them onhold.  &lt;/P&gt;&lt;P&gt;BTW, if you put the elements in that you've talked about in here then your not charging enough  ;)&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Richard.</description><pubDate>Mon, 02 May 2005 07:35:34 GMT</pubDate><dc:creator>R1chard</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>&lt;P&gt;Hi Raphael,&lt;/P&gt;&lt;P&gt;R.a.d Spell is so easy to implement - this will certainly be within the v2.0 KB release. I need to chat wit the folks at Telerik with regards to licensing and protecting the control within my application but i'm sure this will be available &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt;&lt;/P&gt;&lt;P&gt;I'll certainly post more information once the BETA release is available &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt;&lt;/P&gt;</description><pubDate>Thu, 11 Mar 2004 11:17:24 GMT</pubDate><dc:creator>Ryan Healey</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>&lt;P&gt;Hello Ryan&lt;/P&gt;&lt;P&gt;Great! I also saw, that you distribute the InstantForum.Net 3.4 with r.a.d.Spell (very usefull component...) - is there also a chance, that you implement this in the new KB release (spellcheck for articles)?&lt;/P&gt;&lt;P&gt;And... Would be very nice, if I/we can test the beta before final release date! &lt;img src='images/emotions/satisfied.gif' height='20' width='20' border='0' title='Satisfied' align='absmiddle'&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Raphael&lt;/P&gt;</description><pubDate>Thu, 11 Mar 2004 11:12:19 GMT</pubDate><dc:creator>NiM</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>&lt;P&gt;Hello Ryan&lt;/P&gt;&lt;P&gt;Great! I also saw, that you distribute the InstantForum.Net 3.4 with r.a.d.Spell (very useful component...) - is there also a chance, that you implement this in the new KB release (spellcheck for articles)?&lt;/P&gt;&lt;P&gt;And... Would be very nice, if I/we can test the beta before final release date!&lt;img src='images/emotions/satisfied.gif' height='20' width='20' border='0' title='Satisfied' align='absmiddle'&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Raphael&lt;/P&gt;</description><pubDate>Thu, 11 Mar 2004 10:36:06 GMT</pubDate><dc:creator>NiM</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>&lt;P&gt;Hi Raphael,&lt;/P&gt;&lt;P&gt;Thank you for your suggestion. I quite agree this would be more secure. This is currently the way the forums work. I had planned to move all attachments to the database for v2.0 of the knowledge base. This will also provide the ability to search the attached documents within the knowledge base &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt;&lt;/P&gt;&lt;P&gt;With regards to a release date ETA is around end of Q2. Betas will of course be released before this time if you wish to be one of the first. We have many new features to add to this release. A list will be published to the forums soon for feedback before we begin development &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt;&lt;/P&gt;</description><pubDate>Thu, 11 Mar 2004 07:45:56 GMT</pubDate><dc:creator>Ryan Healey</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>&lt;P&gt;I would like to use kb.net as a "document (attachment) and article" management system. Is there a possibility to store the attachment inside the database? I think this is more secure, because no one can access an attachment which is just available for a granted user (request an attachment, check permission, send attachment if granted). Now, everyone can access an attachment in the &lt;a target=_blank href="http://server/instantkb/attachement" target=_blank&gt;http://server/instantkb/attachment&lt;/A&gt; folder (of course just with knowledge about the file name).&lt;/P&gt;&lt;P&gt;would be very nice... and more secure...&lt;/P&gt;&lt;P&gt;Is there a date, when next release/update will be available?&lt;/P&gt;&lt;P&gt;Raphael&lt;/P&gt;</description><pubDate>Thu, 11 Mar 2004 07:38:31 GMT</pubDate><dc:creator>NiM</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>&lt;P&gt;Hi Adam,&lt;/P&gt;&lt;P&gt;Thank you for your feedback. This sounds like a very interesting idea. It would certainly be nice to centralize state management into a manageable class. I'll look into this method a little further. It should be quite simple with the knowledge base to be honest as not to much state information is persisted. Thanks again - i may send you some early examples if thats ok to ensure i've not created any common problems your already aware off &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt;&lt;/P&gt;&lt;P&gt;Thanks again - all the very best and please do keen them suggestions flowing &lt;img src='images/emotions/biggrin.gif' height='20' width='20' border='0' title='Big Grin' align='absmiddle'&gt;&lt;/P&gt;</description><pubDate>Thu, 04 Mar 2004 01:55:00 GMT</pubDate><dc:creator>Ryan Healey</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>One method we have found quite useful is to forgo the session state altogether and using an HTTP module to override the page level USER object.  This allows us to extend the build in user object to support any product specific user properties as well as gives us the ability to not rely at all on a Shared SQL Server or any other centralized state management.  The roles are decode and retreived from the the authentication ticket so that we can extend the built in InRole() method in the User object.  By using a module and extending the built in methods you could just switch out the HTTPmodules that were used to achieve the flexibility to support traditional or cookie based session state management.&lt;BR&gt;&lt;BR&gt;I am sure by now you hate me. &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt; &lt;BR&gt;&lt;BR&gt;If any of this seems if worth your while let me know and I would be more than happy to help in any way.&lt;BR&gt;&lt;BR&gt;Thanks&lt;BR&gt;&lt;BR&gt;Adam Rogas</description><pubDate>Thu, 04 Mar 2004 01:52:00 GMT</pubDate><dc:creator>Adam Rogas</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>&lt;P&gt;Hi Adam,&lt;/P&gt;&lt;P&gt;Thank you for your email. I can certainly understand your concern. One of my aims with v2.0 was to look at a centralized method to handle state management. I would certainly like implement a easy solution which would allow the users to choose from in-process, sql server based or stateserver session management. &lt;/P&gt;&lt;P&gt;I'm actually quite looking forward to developing v2.0 and have some big plans some of which are based around the authentication methods (i would like to offer support for active directory) and also the state management model used. The lessons i learn from the knowledge base in terms of providing multiple options for state management will also be applied to the forums.&lt;/P&gt;&lt;P&gt;I appreciate your concern and may contact you during the development process to ensure we are heading in the right direction and any major updates will not greatly impact your current modifications.&lt;/P&gt;&lt;P&gt;Thanks for your thoughts and suggestions. I'll certainly keep this topic upto date with any future developments &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt;&lt;/P&gt;</description><pubDate>Wed, 03 Mar 2004 02:13:00 GMT</pubDate><dc:creator>Ryan Healey</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>I am not sure how likely this is as I know it makes things harder.&lt;BR&gt;&lt;BR&gt;I was curious if in future versions if you would not rely on the Session state object, to accomplish roles it is not really needed as I can tell you know based off of how you are handling roles with the the forms authentication ticket method already.&lt;BR&gt;&lt;BR&gt;We purchased the first version 1.0 of the KB and loved it.  With most of our web based products we are forced by current usage levels and SLA's to deploy many load balanced servers for each of our applications.  This creates state management issues, and eventually has led us to completely abandon any in memory or centralized session management schemes.  &lt;BR&gt;&lt;BR&gt;When we first installed your KB and realized that the only thing that really needed the session state was the admin an easy solution presented itself. We just disabled session state on the production copy and installed an admin only copy to administer the database. &lt;BR&gt;&lt;BR&gt;&lt;BR&gt;When version 1.2 came out we were very pleased with the new features but we had to do a little work to get the application to not to rely on the session object.&lt;BR&gt;&lt;BR&gt;This is a concern for us as you move towards version 2.0, because as you add more and more of the features that are on the list, the decisions you make about state management are going to affect how much of the product we have to tweek to enable us to use it in a highly available environment.&lt;BR&gt;&lt;BR&gt;Keep up the good work, your product is nice.&lt;BR&gt;&lt;BR&gt;Thanks &lt;BR&gt;&lt;BR&gt;Adam Rogas&lt;BR&gt;Load Ltd.&lt;BR&gt;&lt;a target=_blank href="http://www.load.com/" target=_blank&gt;www.load.com&lt;/A&gt;</description><pubDate>Wed, 03 Mar 2004 02:05:00 GMT</pubDate><dc:creator>Adam Rogas</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>&lt;P&gt;Hi there Ryan.  So far this KB is amazing.  One thing that I'd like to see implemented is an author role so that my in-house users are allowed to add and modify articles but can not delete or make them public until the article is approved - Admin function.  What is the likelyhood of you getting this into the next release?&lt;/P&gt;&lt;P&gt;A user role structure like this:&lt;/P&gt;&lt;P&gt;Web User - Anonymous&lt;BR&gt;Employee&lt;BR&gt;    * View Only (What is there now)&lt;BR&gt;    * Author (Like to see added) Can create &amp;amp; modify&lt;BR&gt;    * Moderator - Create, Modify, Delete, Approve&lt;BR&gt;Administrators&lt;/P&gt;&lt;P&gt;Does that help break it down a little better?&lt;/P&gt;</description><pubDate>Fri, 26 Sep 2003 16:10:00 GMT</pubDate><dc:creator>Daniel Brewerton</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm not able to offer a specific release date for v2.0 of InstantKB.NET. I can assure users this will be available within Q3 this year.&lt;/P&gt;&lt;P&gt;I'm currently busy working on v2.0 of InstantGallery.NET. Once this is released further development on InstantKB.NET will be top priority. This may involve a number of minor releases before we reach v2.0. I will have to see how the enhancements pan out. &lt;/P&gt;&lt;P&gt;Existing users of InstantKB.NET will receive the upgrade to v2.0 free of charge. I'm planning to revise our upgrade policy for this product once we reach version 2.0.&lt;/P&gt;&lt;P&gt;I hope this answers your questions. Please don't hesitate to reply to this post or contact &lt;A href="mailto:support@instantasp.co.uk"&gt;support@instantasp.co.uk&lt;/A&gt; if you have any further questions &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt;&lt;/P&gt;</description><pubDate>Sun, 18 May 2003 08:29:00 GMT</pubDate><dc:creator>Ryan Healey</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>&lt;P&gt;Any date for the v2 release?&lt;/P&gt;&lt;P&gt;Current version is it upgradable FOC to the new version?&lt;/P&gt;&lt;P&gt;Tx&lt;/P&gt;</description><pubDate>Sat, 17 May 2003 05:24:00 GMT</pubDate><dc:creator>Wondrouz</dc:creator></item><item><title>RE: Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;Some great suggestions there &lt;img src='images/emotions/wow.gif' height='20' width='20' border='0' title='Wow' align='absmiddle'&gt; - I've answered each question below. If you have any further questions please don't hesitate to post a reply or contact me on &lt;A href="mailto:support@instantasp.co.uk"&gt;support@instantasp.co.uk&lt;/A&gt; &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt;&lt;/P&gt;&lt;P&gt;1. I plan to add the ability for users to login in v2. You will have the ability to create categories and assign an access level to the category. Based on the members privileges only specific categories will be displayed. This has been the most requested feature since the kb release.&lt;/P&gt;&lt;P&gt;2. Yep Internal Only documents and categories will be available within v2.0.&lt;/P&gt;&lt;P&gt;3. This is a great suggestion. I will certainly look into this idea. The attachments would be quite easy to do this with. The external links and related articles maybe a little tricky. I'll look into the possibility for v2.0.&lt;/P&gt;&lt;P&gt;4. I plan to improve the current work flow for the kb articles. I'm not 100% sure what you mean by have a section for ? - Maybe we could chat on MSN once i'm close to adding this feature. I'd be more than happy to discuss and add this feature if required.&lt;/P&gt;&lt;P&gt;5. Good suggestion - i'll add this to v2.0.&lt;/P&gt;&lt;P&gt;6. Oh my god - these suggestions are getting better &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt; - Again i will certainly look into this for a future release. I'll add all your items to my wish list. Great idea.&lt;/P&gt;&lt;P&gt;7. This could be an optional feature. If this is not within v2, i'll certainly add this in a release at some point &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt;&lt;/P&gt;&lt;P&gt;8. I'll look into this possibility. What problems is it causing at the moment running within a https:// space. Have you tested this ?&lt;/P&gt;&lt;P&gt;9.You could change this from within the web.config. However i may move all configuration information into a database with v2.0.&lt;/P&gt;&lt;P&gt;10. This would be quite easy to do. I plan to great groupings for KB members, this would allow you to globally set permissions or remove access per group or per user. This should allow you to do this.&lt;/P&gt;&lt;P&gt;11. I've already looked at integrating the two applications. I plan to get them both working with each other for v3 &lt;img src='images/emotions/smile.gif' height='20' width='20' border='0' title='Smile' align='absmiddle'&gt;&lt;/P&gt;&lt;P&gt;I hope that has answered your questions. If you have any further queries please don't hesitate to contact me. I'm more than happy to help.&lt;/P&gt;</description><pubDate>Tue, 13 May 2003 07:48:00 GMT</pubDate><dc:creator>Ryan Healey</dc:creator></item><item><title>Additional Security Features</title><link>http://community.instantasp.co.uk/Topic541-27-1.aspx</link><description>&lt;P&gt;Could you layout the security design plans you have for V2?&lt;/P&gt;&lt;P&gt;I would like to be able to:&lt;/P&gt;&lt;P&gt;1. Vary security by knowledgebase and by categories/folders below the knowledgebase.&lt;/P&gt;&lt;P&gt;2. To declare an article as internal only.&lt;/P&gt;&lt;P&gt;3. To have internal/external designations on parts of an article.  Notes, links, attachments could be internal only or Public and would display appropriately to the person viewing the article.  This ability to have linked internal information is vital.&lt;/P&gt;&lt;P&gt;4. To have a section for Publisher / Editor / Review / Approval notes that would only be available to those with appropriate editting or workflow rights.&lt;/P&gt;&lt;P&gt;5. To have a section for mynotes or mycomments which I can attach and be the sole viewer of that info.&lt;/P&gt;&lt;P&gt;6. To have publication dates (Start and End) on articles with the ability to search unreleased or expired articles for those individuals with the approriate rights.&lt;/P&gt;&lt;P&gt;7. To have required user account password changes occur on a scheduled basis.&lt;/P&gt;&lt;P&gt;8. To support https: 128 bit encryption minimally to maintain information security to the browser.&lt;/P&gt;&lt;P&gt;9. Selectable timeout for inactivity&lt;/P&gt;&lt;P&gt;10. Security allowed based on an organization/employer affiliation.  eg. if I open my knowledgebase up to my customers and one of my customers discontinues it relationship with us, I want to term or PEND all the associated subscribers to my knowledgebase(s)&lt;/P&gt;&lt;P&gt;11. I would like the security for forums to be shared or consistent with the knowledgebase, so maintenance is as minimal as possible.&lt;/P&gt;</description><pubDate>Tue, 13 May 2003 07:27:00 GMT</pubDate><dc:creator>Tom Grumbling</dc:creator></item></channel></rss>