Skip to main content

Posts

Showing posts with the label Validate

Weak software design - Restrict user access in the web applications

Today I want to talk about a smell that I way sometimes on web application. We will start with a short story to create a context for our smell. One day a request comes to the developer that he needs to create a page where the user can view a list of items. For each item the user can view details, edit an item and delete it. After a while the manager changes the request: “Only specific users can edit or delete items from the list”. Our developer based on the role of a user identifies what user can edit or delete items and for the rest of the user he decides to hide the two buttons. When we look over the code something is wrong. If the user knows the URL for the edit page of an item or for deletion, he can edit and delete any items even if is not an admin. We should never trust inputs that come from users. Every time we should validate on the server side the data from the user and also if he has rights to do execute a command or view a specific page. In MVC application is very simpl...

XXX takes a dependency on Microsoft.VCLibs.110 framework but is missing the framework dependency declaration in the manifes.

In cazul in care incercati sa validati aplicatie Metro style App pentru Windows 8 si va treziti cu urmatoarea eroare: XXX takes a dependency on Microsoft.VCLibs.110 framework but is missing the framework dependency declaration in the manifes. o sa fie destul de ciudat de rezolvat si gasit cauza daca proiectul vostru este un proiect XAML cu C# sau HTML 5 cu JavaScript. By default voi nu aveti nici o referinta la nici un proiect C++ care sa va genereze aceasta dependinta. In cazul in care ati folosit librarii externe precum cele pentru Bing Maps, in mod indirect o sa aveti o dependinta spre aceasta librarie. Daca am fi fost intr-un proiect de C++ si nu C# aceasta dependinta ar fi fost adaugata automat. Adaugarea acestei dependinte trebuie sa fie facuta din fisierul "Package.manifest". Din pacate nu se poate face dintr-o interfata grafica prietenoasa. O sa fie nevoie sa deschideti acest fisier dintr-un editor XML sau test si sa adaugati sub nodul "Package" urmatorul c...

Caz in care IValidatableObject.Validate nu este apelat

Daca in aplicatia voastra MVC in loc de Enterprise library pentru validare o sa fiti surprinsi ca exista cazuri cand metoda pentru validare nu este apelata asa cum v-ati astepta. Folosind atributele HasSelfValidate si SelfValidate, putem sa validam un obiect. Atributul HasSelfValidate ne spune daca obiectul curent are un mecanism propiu de validare. Metoda care face validarea in interiorul obiectului nostru trebuie sa aibe atributul SelfValidation si urmatorul antet: void numeMetoda( ValidationResults validationResults ) In cazul in care obiectul nu este valid putem sa adaugam pe validationResults mesajul dorit impreuna cu alte informatii precum: nume propietate si referinta la obiectul care nu este valid. [HasSelfValidate] public class Person { public int Age { get; set; } public int Name { get; set; } [SelfValidation] public void Validate(ValidationResults validationResults) { if( Age < 0 ) { validationResults.AddResul...