<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Feature Access Security in ArcGIS JavaScript Maps SDK Questions</title>
    <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/feature-access-security/m-p/67085#M5880</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I pondered which forum/section I should post this, but ultimately I am using the JavaScript API to develop this application so I am hoping I can find some security savvy folks to help.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I manage some in house ArcGIS servers where we plan to host our own Feature access services. I have some map services that I want to allow authorized staff to create new point, lines and polygons using a web application hosted on another server. I can authenticate these users on this other server. The web application will use the REST API from the ARCGIS server for these edits, however I need a good simple way to protect the Feature Access from unauthorized/anonymous users from the Create/Edit/Delete operations.&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I don't want to use Windows Active Directory because we have a lot of public access to other map services which could interrupt current services. I also want to maintain access through the ArcGIS.com on these other public services, so any server level security changes need to be sensitive to this. I know I can set security specific to the entire service (Public or private) as well as folder specific permissions. I do have Roles for Users, Publishers and Admin that can use local and Active Directory but it starts to become very confusing. I am hoping for an easy way to implement a simple security measure to only allow access to my authenticated users, without extra steps for the users to make.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;There is a lot of articles on ArcGIS security, which is part of my problem, there is just too much to understand.&amp;nbsp; I was hoping someone here could help guide me on how to set this this from the Web App to the ArcGIS server. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Jason&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Feb 2013 12:45:20 GMT</pubDate>
    <dc:creator>KristenJones1</dc:creator>
    <dc:date>2013-02-28T12:45:20Z</dc:date>
    <item>
      <title>Feature Access Security</title>
      <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/feature-access-security/m-p/67085#M5880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I pondered which forum/section I should post this, but ultimately I am using the JavaScript API to develop this application so I am hoping I can find some security savvy folks to help.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I manage some in house ArcGIS servers where we plan to host our own Feature access services. I have some map services that I want to allow authorized staff to create new point, lines and polygons using a web application hosted on another server. I can authenticate these users on this other server. The web application will use the REST API from the ARCGIS server for these edits, however I need a good simple way to protect the Feature Access from unauthorized/anonymous users from the Create/Edit/Delete operations.&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I don't want to use Windows Active Directory because we have a lot of public access to other map services which could interrupt current services. I also want to maintain access through the ArcGIS.com on these other public services, so any server level security changes need to be sensitive to this. I know I can set security specific to the entire service (Public or private) as well as folder specific permissions. I do have Roles for Users, Publishers and Admin that can use local and Active Directory but it starts to become very confusing. I am hoping for an easy way to implement a simple security measure to only allow access to my authenticated users, without extra steps for the users to make.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;There is a lot of articles on ArcGIS security, which is part of my problem, there is just too much to understand.&amp;nbsp; I was hoping someone here could help guide me on how to set this this from the Web App to the ArcGIS server. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Jason&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2013 12:45:20 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/feature-access-security/m-p/67085#M5880</guid>
      <dc:creator>KristenJones1</dc:creator>
      <dc:date>2013-02-28T12:45:20Z</dc:date>
    </item>
  </channel>
</rss>

