Instant Web Publishing Guide

Table Of Contents
Chapter 5
|
Testing, monitoring, and securing your site 41
1 If an account limits record-by-record browse privileges but does not limit the privilege to delete records,
it is possible for users to delete records they cannot view.
1 If the same account opens related files, the related data is displayed on layouts containing related fields.
1 Instant Web Publishing uses the accounts and privilege sets defined in FileMaker Pro for the best security.
For more information, see the FileMaker Pro User’s Guide.
1 Never store sensitive documents or databases inside the Web folder. With FileMaker Pro, you can put
images to share with container fields or static HTML pages that you want to publish in the Web folder
inside the FileMaker Pro folder, but due to web server architecture, all files in the Web folder are
accessible and might be deleted by others.
1 Carefully review your scripts to make sure they are web compatible and that the combination of steps
don’t produce unexpected results. For more information, see
“FileMaker scripts and Instant Web
Publishing” on page 34.
1 As operating system vendors continue to patch security problems, they may disable certain features, often
in conjunction with security settings within the user’s web browser. Such changes might disable or change
the behavior of web viewers in Instant Web Publishing. If such changes affect your solution, FileMaker
recommends that you tell users how to change security settings in their browsers to allow web viewers to
function properly, or ensure that the URLs used by your web viewers are for trusted web sites only.