<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Yehohanan7</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Yehohanan7"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Yehohanan7"/>
		<updated>2026-05-05T15:40:19Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Yehohanan7&amp;diff=29699</id>
		<title>User:Yehohanan7</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Yehohanan7&amp;diff=29699"/>
				<updated>2008-05-22T14:07:45Z</updated>
		
		<summary type="html">&lt;p&gt;Yehohanan7: /* Accidental leaking of sensitive information through data queries */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 	Access control enforced by presentation layer ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Definition:]] &lt;br /&gt;
&lt;br /&gt;
	Enforcing access control in the presentation layer means that the developer does not show buttons and links for functions and assets that are not authorized for the user&lt;br /&gt;
&lt;br /&gt;
Example in our application:&lt;br /&gt;
&lt;br /&gt;
The payment button will be not shown in the payment page if the holiday is already booked.&lt;br /&gt;
&lt;br /&gt;
[[Attacks]]&lt;br /&gt;
&lt;br /&gt;
Forced Browsing&lt;br /&gt;
	&lt;br /&gt;
&lt;br /&gt;
[[Defense]]&lt;br /&gt;
&lt;br /&gt;
Access control must be performed in the business layer, not only the presentation layer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Accidental leaking of sensitive information through data queries ==&lt;br /&gt;
&lt;br /&gt;
[[SQL Injection]]&lt;/div&gt;</summary>
		<author><name>Yehohanan7</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Yehohanan7&amp;diff=29689</id>
		<title>User:Yehohanan7</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Yehohanan7&amp;diff=29689"/>
				<updated>2008-05-22T09:32:03Z</updated>
		
		<summary type="html">&lt;p&gt;Yehohanan7: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== 	Access control enforced by presentation layer ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Definition:]] &lt;br /&gt;
&lt;br /&gt;
	Enforcing access control in the presentation layer means that the developer does not show buttons and links for functions and assets that are not authorized for the user&lt;br /&gt;
&lt;br /&gt;
Example in our application:&lt;br /&gt;
&lt;br /&gt;
The payment button will be not shown in the payment page if the holiday is already booked.&lt;br /&gt;
&lt;br /&gt;
[[Attacks]]&lt;br /&gt;
&lt;br /&gt;
Forced Browsing&lt;br /&gt;
	&lt;br /&gt;
&lt;br /&gt;
[[Defense]]&lt;br /&gt;
&lt;br /&gt;
Access control must be performed in the business layer, not only the presentation layer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Accidental leaking of sensitive information through data queries ==&lt;/div&gt;</summary>
		<author><name>Yehohanan7</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Yehohanan7&amp;diff=29688</id>
		<title>User:Yehohanan7</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Yehohanan7&amp;diff=29688"/>
				<updated>2008-05-22T09:30:28Z</updated>
		
		<summary type="html">&lt;p&gt;Yehohanan7: New page: 	Access control enforced by presentation layer  Definition:   	Enforcing access control in the presentation layer means that the developer does not show buttons and links for functions ...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;	Access control enforced by presentation layer&lt;br /&gt;
&lt;br /&gt;
Definition: &lt;br /&gt;
&lt;br /&gt;
	Enforcing access control in the presentation layer means that the developer does not show buttons and links for functions and assets that are not authorized for the user&lt;br /&gt;
&lt;br /&gt;
Example in our application:&lt;br /&gt;
&lt;br /&gt;
The payment button will be not shown in the payment page if the holiday is already booked.&lt;br /&gt;
&lt;br /&gt;
Attacks&lt;br /&gt;
&lt;br /&gt;
	Forced Browsing&lt;br /&gt;
	&lt;br /&gt;
&lt;br /&gt;
Defense&lt;br /&gt;
&lt;br /&gt;
	Access control must be performed in the business layer, not only the presentation layer.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
	Accidental leaking of sensitive information through data queries&lt;/div&gt;</summary>
		<author><name>Yehohanan7</name></author>	</entry>

	</feed>