Index: openacs-4/packages/acs-core-docs/www/security-requirements.html =================================================================== RCS file: /usr/local/cvsroot/openacs-4/packages/acs-core-docs/www/security-requirements.html,v diff -u -r1.22.2.1 -r1.22.2.2 --- openacs-4/packages/acs-core-docs/www/security-requirements.html 5 Jul 2004 19:47:31 -0000 1.22.2.1 +++ openacs-4/packages/acs-core-docs/www/security-requirements.html 1 Nov 2004 23:40:12 -0000 1.22.2.2 @@ -1,17 +1,17 @@ -Security Requirements

Security Requirements

By Richard Li

+Security Requirements

Security Requirements

By Richard Li

OpenACS docs are written by the named authors, and may be edited by OpenACS documentation staff. -

Introduction

+

Introduction

This document lists the requirements for the security system for the OpenACS. -

Vision Statement

+

Vision Statement

Virtually all web sites support personalized content based on user identity. The level of personalization may be as simple as displaying the name of the user on certain pages or can be as sophisticated as dynamically recommending sections of site that the user may be interested in based on prior browsing history. In any case, the user's identity must be validated and made available to the rest of the system. In addition, sites such as ecommerce vendors require that the user identity be securely validated. -

Security System Overview

+

Security System Overview

The security system consists of a number of subsystems.

Signed Cookies

Cookies play a key role in storing user information. However, since they are