Home 
 Product 
 Editions 
 Security 
 Download 
 Buy 
 Support 
 Training 
 Partners 
 About 
Bitrix Site Manager Home
4500 templates for Bitrix Site Manager
Bitrix Site Manager Home Home / Security / Product security

Authorization preserving

Product security
Authorization system
User identification
Password change
Authorization preserving
Access permission distribution
Access control
Data encryption
SiteUpdate
Plastic cards handling
External data and variables handling

"Bitrix Site Manager really turned out to be the solution of our problems. We believe that we are constantly improving our business and relations with our customers and we are doing it with Bitrix Site Manager."
Alexander Lyskovsky,
Alawar Entertainment


Powered by
Bitrix Site Manager:





Remember me on this computer
  Forgot your password?
  Register

The Bitrix Site Manager software implements a mechanism enabling users to preserve authorization in the browser and computer from which they visit the site after the first login. It is intended for easier handling of the site and forums, e-store orders, as well as simplifying working with dealer sections and other private site sections.


This mechanism can be enabled or disabled in the “System settings -> Settings -> Kernel module settings”, variable “Allow authorization caching”. The default value is “allow”.


If the authorization preserving is allowed in the system settings, the user is offered to check the option “Remember me on this computer” when authorizing. In this case, after the successful authorization the system calculates the hash value unique for both this user and this site, stores the calculated value in the server database, and transfers it to the user in the form of cookie. Note that this variable contains neither username nor password and cannot be used to restore the initial information.


When logging in the site with the credentials hash stored in cookie and the authorization preserving allowed, the system checks a variable calculated during the last authorization and stored in cookie on client side. In case of match, a user is automatically authorized without entering the username and password.


It is important to consider that a user can preserve the authorization not only on his computer but also in an internet café or a club, and in this case, another visitor theoretically can obtain access to the user personal data.


The authorization preserving function is very convenient for users and simplifies work with the site. However, if you develop sites with highly confidential information it is recommended to disable the authorization preserving or thoroughly inform users how to use this possibility safety for them and for the project.

To ensure the required level of security when using the external authorization mechanism or the module “ActiveDirectory/LDAP Integration”, the authorization of external users from other applications is not stored irrespective of the kernel module settings.






Search

0 Your shopping cart is empty
0 Personal section

Bitrix Site Manager Version 7.0

Secure Web Application


© 2001-2008 Bitrix, Inc. Bitrix® is a registered trademark of Bitrix, Inc.
Powered by Bitrix Site Manager - Content Management & Portal Solutions
 Contacts   Privacy Policy   Search   Site Map