<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
<channel>
<title>CodeStore.net comments on "A NotesSession JavaScript Object"</title>
<description>Replies to blog "A NotesSession JavaScript Object" on codestore.net.</description>
<link>http://www.codestore.net/</link>
<lastBuildDate>Sat, 3 Feb 2007 06:58:00 +0100</lastBuildDate>
<atom:link href="http://www.codestore.net/store.nsf/blog.xml?Open=20070226" rel="self" type="application/rss+xml" />

<item>
	<title>Reply from Lee Powell</title>
	<pubDate></pubDate>
	<author>Lee Powell</author>
	<description><![CDATA[ 
		<p>Hi Jake, this is a very interesting article - I found it very helpful to me in nailing a javascript framework to use on a personal project - so, thank you! How advanced are you on the DExt framework?</p>
		<p>In terms of security, I see web apps almost every day - on other platforms where sql injection and helpful error messages, can lead a hacker into many so called secure sites and databases - fortunately, most people know very little about Domino. In this case exposure is minimal and still does not overide Domino database security. </p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=29467F979F0B4180852572B700421E20"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_29467F97</link>
</item><item>
	<title>Reply from Renato De Marchi</title>
	<pubDate>Sat, 3 Feb 2007 06:58:00 +0100</pubDate>
	<author>Renato De Marchi</author>
	<description><![CDATA[ 
		<p>Dear Jake,</p>
		<p>Yours articles helped me a lot in order to learn to develop in Domino platform.</p>
		<p>I have found your articles on Yahoo-ext library very interesting .</p>
		<p>You can enclose the database, or mailed me, to unload to the study ends?</p>
		<p>Thanks in advance.</p>
		<p>p.s. Sorry for my english </p>
		<p>and greetings from Venice</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=27AE9920DB78920F852572920041C7AA"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_27AE9920</link>
</item><item>
	<title>Reply from Michael</title>
	<pubDate>Wed, 28 Feb 2007 22:19:00 +0100</pubDate>
	<author>Michael</author>
	<description><![CDATA[ 
		<p>The keyboard drag feature is in the help docs as Ctrl-Shift-arrow keys  but it works with the Home and End keys as well.</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=CF432799D1A4475A8525729100124115"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_CF432799</link>
</item><item>
	<title>Reply from Michael</title>
	<pubDate>Wed, 28 Feb 2007 16:33:00 +0100</pubDate>
	<author>Michael</author>
	<description><![CDATA[ 
		<p>Ext Alpha 6 is up with a hidden gem (Ctrl-Shift-Home) on any form.</p>
		<p>Out of curiousity, I tried this on my Notes workspace and discovered that I could "drag"  database icon(s) without using the mouse, to another location on my workspace including other tabs.  I can't count how many times I've started a mouse drag to another workspace tab only to have overshot the tab and have every location turned into a 'no-drop' zone along with crossed out circle as a mouse pointer.</p>
		<p>It's not ground breaking, but definitely a technique that I'll use from now on.</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=C353F66504062CE9852572900076714B"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_C353F665</link>
</item><item>
	<title>Reply from Jake Howlett</title>
	<pubDate>Tue, 27 Feb 2007 04:22:00 +0100</pubDate>
	<author>Jake Howlett</author>
	<description><![CDATA[ 
		<p>Hi Tommy. Maybe I was a little over-defensive in my reply. Sorry about that ;o)</p>
		<p>It's running a blog that does it to you. You become all defensive and bite back at anything at all. I think I talked before about how it sometimes feels a bit like there's a desire to prove me wrong. Probably just me being paranoid though. </p>
		<p>Having re-read your post today I see it was all well meant and constructive commentary. My reply has a tone to it that I didn't really intend. Such is the problem of this form of communication.</p>
		<p>Anyway, don't pretend you've never written an app where - for security - you've relied on user ignorance. Come on, we've all done it.</p>
		<p>Jake</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=049017C0E980F64F8525728F003386B9"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_049017C0</link>
</item><item>
	<title>Reply from Tommy Valand</title>
	<pubDate>Tue, 27 Feb 2007 00:43:00 +0100</pubDate>
	<author>Tommy Valand</author>
	<description><![CDATA[ 
		<p>I only wanted to point out that every (non-native) object/property in JS is open to be read/overwritten by very simple means, not to trample on your excellent initiative for making it easier for Notes developers to make advanced applications on the web.</p>
		<p>Pardon my arrogance.</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=0E3B907C93DAD16B8525728F001F6FE6"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_0E3B907C</link>
</item><item>
	<title>Reply from Jake Howlett</title>
	<pubDate>Mon, 26 Feb 2007 16:31:00 +0100</pubDate>
	<author>Jake Howlett</author>
	<description><![CDATA[ 
		<p>Thanks for the links guys and the explanation Bill.</p>
		<p>Tommy. Yeah, yeah, very impressive. Obviously it's a doddle to "hack" it, but it's not meant as a replacement for Notes-side access control. If they' have reader access they can do what they like to the DEXT properties -- it's not going to magically give them author rights to the database now is it!?</p>
		<p>Horses for courses init.</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=F12C2C8881B3C2438525728E0076448A"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_F12C2C88</link>
</item><item>
	<title>Reply from Tommy Valand</title>
	<pubDate>Mon, 26 Feb 2007 15:36:00 +0100</pubDate>
	<author>Tommy Valand</author>
	<description><![CDATA[ 
		<p>Sorry to double post (no edit post-button).</p>
		<p>If you're interested in learning about the scope of "this", Douglas Crockford (the father of JSON) has written a simple but informative article about "Private Members in JavaScript": {<a rel="nofollow" href="http://www.crockford.com/javascript/private.html">Link</a>}</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=9CEA5D434FBB78668525728E00712F66"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_9CEA5D43</link>
</item><item>
	<title>Reply from Tommy Valand</title>
	<pubDate>Mon, 26 Feb 2007 14:51:00 +0100</pubDate>
	<author>Tommy Valand</author>
	<description><![CDATA[ 
		<p>I also have some security-concerns.</p>
		<p>To set full "client-side access". A simple bookmarklet will do.</p>
		<p>javascript:(function(){access=YAHOO.DEXT.Session.User.Access; for(item in access){if(typeof access[item] === "boolean"){access[item]= true;}}})()</p>
		<p>I would think that a greasemonkey-script, or a debugger like Firebug (using breakpoints) can help the user to override the access-variables before the layout is initialized..</p>
		<p>If you don't expose any unsecured server-side agents/etc, this will not be a problem. </p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=4FA75D0C378C33B78525728E006D1DD8"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_4FA75D0C</link>
</item><item>
	<title>Reply from Brian Miller</title>
	<pubDate>Mon, 26 Feb 2007 14:38:00 +0100</pubDate>
	<author>Brian Miller</author>
	<description><![CDATA[ 
		<p>@Jake:</p>
		<p>1. Read this: {<a rel="nofollow" href="http://www.quirksmode.org/js/this.html">Link</a>}</p>
		<p>In fact, the more time you spend reading quirksmode, the more this kind of thing will click.  You might even consider buying a copy of PPK's book for reference.</p>
		<p>2. One of the simplest functions in YUI is the namespace function, which is there to save the Y folks some typing.  They use multiple levels of objects for namespacing, so if they want to create a new sub-library, they can start with:</p>
		<p>YAHOO.namespace( 'foo.bar.baz' );</p>
		<p>instead of: </p>
		<p>YAHOO.foo = {};</p>
		<p>YAHOO.foo.bar = {};</p>
		<p>YAHOO.foo.bar.baz = {};</p>
		<p>I hope that explains things a bit.</p>
		<p>@Bill E:</p>
		<p>I've had some spirited discussions with people about the security issue.  What it boils down to, in my mind, is that the information coming out of the server for this sort of thing is the same, on the wire, as what you're pulling down in a regular domino-generated web page.  Having it in JS or JSON is no better or worse than plain HTML.  If you're worried, use HTTPS.  If you're still worried, pack the script before you send it.</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=076636EB1E56FA128525728E006BEA71"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_076636EB</link>
</item><item>
	<title>Reply from Jake Howlett</title>
	<pubDate>Mon, 26 Feb 2007 12:50:00 +0100</pubDate>
	<author>Jake Howlett</author>
	<description><![CDATA[ 
		<p>That occurred to me as well Bill. Can't see anything in there that could be considered harmful though. Apart from, maybe, the server build, which might be of use to a hacker. Apart from that there's nothing to worry about.</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=55888534F8D0B9248525728E0061FC01"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_55888534</link>
</item><item>
	<title>Reply from Bill E</title>
	<pubDate>Mon, 26 Feb 2007 12:24:00 +0100</pubDate>
	<author>Bill E</author>
	<description><![CDATA[ 
		<p>From a security perspective, is it really ok to publish some of the information in the source for JS? Would it pass a security audit? Looks great, though! =)</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=9224D26A4C6A12B68525728E005FA3B0"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_9224D26A</link>
</item><item>
	<title>Reply from Jake Howlett</title>
	<pubDate>Mon, 26 Feb 2007 09:41:00 +0100</pubDate>
	<author>Jake Howlett</author>
	<description><![CDATA[ 
		<p>Hi Brian. I'll look in to this. As what I am doing is mainly a case of standing on the shoulders of giants I am merely doing as they do.</p>
		<p>What I need to do though is take a step back and start to understand more of what I am doing in terms of core JavaScript. For example, the "this" keyword is causing me some confusion and I find myself guessing how code works instead of understanding how. Always dangerous.</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=D5A1BD47191953BF8525728E0050B6CC"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_D5A1BD47</link>
</item><item>
	<title>Reply from Brian Miller</title>
	<pubDate>Mon, 26 Feb 2007 09:30:00 +0100</pubDate>
	<author>Brian Miller</author>
	<description><![CDATA[ 
		<p>Good stuff!</p>
		<p>I wouldn't bother using YAHOO.namespace(), though, because you're only going one level down, and you're reassigning the namespace anyway.  Just use "DEXT = {}", and you've made it simpler while saving youself an object.</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=2B9900BE655C0A358525728E004FB6CE"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_2B9900BE</link>
</item><item>
	<title>Reply from Jack Ratcliff</title>
	<pubDate>Mon, 26 Feb 2007 08:14:00 +0100</pubDate>
	<author>Jack Ratcliff</author>
	<description><![CDATA[ 
		<p>Awesome! I covered how to create a NotesSession and a NotesDocument obect in my @Formulas meet Ajax session at this year's Lotusphere. Your approach is slightly different than mine though but they accomplish the same thing. I'll blog about it later today to show everyone my approach. </p>
		<p>I know most people are glued to what we've been able to do with the web UI of Domino apps using Ext. However, I hope everyone realizes how cool this other is. IBM wouldn't do it for us but you and I and maybe some others will and that is to build "JavaScript Classes" for the Domino Objects.</p>

		<p><a href="http://www.codestore.net/store.nsf/reply?OpenForm&ParentUNID=D86CE8AF754EF3658525728E0048C688"><img border="0" src="http://www.codestore.net/store.nsf/images/rss_reply.gif" alt="Click here to post a response" /></a></p>
	]]></description>
	<link>http://www.codestore.net/store.nsf/unid/BLOG-20070226?OpenDocument#DOC_D86CE8AF</link>
</item>

</channel>
</rss> 
