Quantcast
Channel: SharePoint 2010 - Setup, Upgrade, Administration and Operations forum
Viewing all articles
Browse latest Browse all 13778

Sharepoint 2010 FBA Session cookie shared with Microsoft Word or other client applications

$
0
0

Hi,

We have external facing SharePoint 2010 FBA WA for document sharing with clients. Users are uploading and sharing documents externally and allows client applications like Word, Excel, etc. to open documents directly without allowing user to download the documents. But our security team is finding this ricky as we are using Persistent cookies over Session cookie to implement such scenario. They are saying with Persistent cookie anybody can access the site without authentication.

Specifically, If users forgot to log off and just close the browser from the site and its a public computer anybody can use that machine and access the site from the history and SharePoint will not prevent them to do this as cookie is not expired because of Persistent cookie.

My question is

Can we use Session cookie and also be able to pass the cookie information to client applications (Word, Excel, etc.)?

Thanks,

Bhavin


Viewing all articles
Browse latest Browse all 13778

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>