WebDirect Guide

Table Of Contents
Chapter 4 | Testing, monitoring, and securing a solution 31
3. Select Enable logging for Web Publishing, then click Save.
For a list of error codes and descriptions, see FileMaker Pro Help.
Keep these points in mind:
1 Entries are added to a log file in the order that FileMaker Server processes them.
1 You can also use FileMaker Pro functions to track user activity. See FileMaker Pro Help.
Securing your data
When you publish a FileMaker WebDirect solution, it is very important to determine who should
have access to the data and to specify which tasks users can perform. For more information on
securing your database, see FileMaker
Pro Help.
Keep these security considerations in mind when publishing solutions on the web:
1 User accounts operate the same regardless of which technologies clients use to access your
solutions. For example, if you create an account that restricts access to deleting records, users
who access the solution with that account name and password will not be able to delete
records, whether they access the data from FileMaker
WebDirect, an ODBC data source, or
FileMaker
Pro.
1 When enabling access to solutions via FileMaker WebDirect, assign accounts and privilege
sets to web users rather than providing access to all users.
1 If an account limits record-by-record browse privileges but does not limit the privilege to delete
records, it is possible for users to delete records they cannot view.
1 Consider using Secure Sockets Layer (SSL) encryption to secure communication between
FileMaker
WebDirect and FileMaker Server. See “Enabling SSL encryption” on page 27.
1 As operating system vendors continue to patch security problems, they may disable certain
features, often in conjunction with security settings within the user’s web browser. Such
changes might disable or change the behavior of web viewers in FileMaker
WebDirect. If such
changes affect your solution, tell users how to change security settings in their browsers to
allow web viewers to function properly, or ensure that the URLs used by your web viewers are
for trusted webpages only.