• Post Reply Bookmark Topic Watch Topic
  • New Topic
programming forums Java Mobile Certification Databases Caching Books Engineering Micro Controllers OS Languages Paradigms IDEs Build Tools Frameworks Application Servers Open Source This Site Careers Other Pie Elite all forums
this forum made possible by our volunteer staff, including ...
Marshals:
  • Campbell Ritchie
  • Paul Clapham
  • Ron McLeod
  • Jeanne Boyarsky
  • Tim Cooke
Sheriffs:
  • Liutauras Vilda
  • paul wheaton
  • Henry Wong
Saloon Keepers:
  • Tim Moores
  • Tim Holloway
  • Stephan van Hulst
  • Carey Brown
  • Frits Walraven
Bartenders:
  • Piet Souris
  • Himai Minh

Preventing access to .js files

 
Ranch Hand
Posts: 315
  • Mark post as helpful
  • send pies
    Number of slices to send:
    Optional 'thank-you' note:
  • Quote
  • Report post to moderator

How can I prevent the user from downloading my javascript file in web application deployed in tomcat.

many thanks
neeraj.
 
Rancher
Posts: 1337
  • Mark post as helpful
  • send pies
    Number of slices to send:
    Optional 'thank-you' note:
  • Quote
  • Report post to moderator
You can't. If the browser can access .js files, then so can the user directly. What are you trying to achieve?
 
Neeraj Vij
Ranch Hand
Posts: 315
  • Mark post as helpful
  • send pies
    Number of slices to send:
    Optional 'thank-you' note:
  • Quote
  • Report post to moderator
I want to encrypt the request parameters before submitting the request and I don't want the user being able to view the method used for encryption in the .js file.

Many Thanks
Neeraj.
 
Lester Burnham
Rancher
Posts: 1337
  • Mark post as helpful
  • send pies
    Number of slices to send:
    Optional 'thank-you' note:
  • Quote
  • Report post to moderator
As I said, impossible (and not a god idea to begin with). If you want encrypted communication, why not use HTTPS?
 
Saloon Keeper
Posts: 25477
180
Android Eclipse IDE Tomcat Server Redhat Java Linux
  • Mark post as helpful
  • send pies
    Number of slices to send:
    Optional 'thank-you' note:
  • Quote
  • Report post to moderator
JavaScript files run on the client, therefore the client has to be supplied with copies of them, therefore they MUST be downloadable. Q.E.D.

You're also providing yet another example of why people shouldn't try to invent their own security systems. Security is NOT an "All You Have To Do Is..." operation. It's complex, it's difficult, it requires a lot of knowledge, and even professionally-designed systems periodically turn up exploitable. Most "clever amateur" systems can't stand 5 minutes in the sun. So we recommend that you learn to use the existing frameworks and channels rather than try and invent something.
 
If you want to look young and thin, hang around old, fat people. Or this tiny ad:
Free, earth friendly heat - from the CodeRanch trailboss
https://www.kickstarter.com/projects/paulwheaton/free-heat
reply
    Bookmark Topic Watch Topic
  • New Topic