Home » Press Releases New ICEfaces White Paper Detai ...

Press Releases by JavaScriptSearch

New ICEfaces White Paper Details Robust Security Solution For Ajax-Based Rich Web Applications

“Enterprise Ajax Security with ICEfaces” Demonstrates That Proven, Server-Side Java EE Security Architecture Can be Preserved by “Ajaxifying” JSF with ICEfaces

September 13, 2007; 02:54 AM

CALGARY, Alberta--ICEsoft Technologies, Inc., a leading provider of enterprise Ajax solutions, today announced the release of Enterprise Ajax Security with ICEfaces, a new white paper providing a pioneering solution to the security problem posed by rich Internet applications employing Ajax techniques. By using ICEfaces, the unique integrated Ajax application framework for Java EE, developers can leverage the trusted, proven security characteristics of Java EE, thereby avoiding the security gaps inherent in client-centric Ajax implementations.

Typical Ajax techniques violate the fundamental security rule of the Web security modeldont trust the client, noted Stephen Maryka, Chief Technology Officer of ICEsoft Technologies Inc. and author of the white paper. Client-centric Ajax creates a number of security problems for the enterprise, from business logic residing outside the server environment, to multiple sets of validation logic necessary to verify data being submitted back to server-side applications. By using the inherent, existing security of Java EE, these issues are sidestepped without compromising the performance or convenience made possible with rich Web solutions.

Ajaxifying JSF

While security has always been a hallmark of Java EE (Enterprise Edition), a link must be established between the Java environment and Ajax. JavaServer Faces (JSF), the most recent addition to the Java EE stack, combined with ICEfaces, provides the solution.

As explained in the white paper, ICEfaces can be used to establish Ajax functionality in JSF without compromising the server-centric nature of the Java EE framework. ICEfaces offers a lightweight Ajax Bridge that enables both partial data submission from the user, and incremental DOM updates to the browser client. The partial submit mechanism is built into the ICEfaces component suite, so the developer has control over the mechanism on a component level basis; on the return side, the framework uses a technique called Direct-to-DOM rendering with incremental update to distill only those DOM changes necessary to update the Web page.

Enterprise Ajax Security with ICEfaces convincingly shows how Ajaxifying JSF can provide the security required for rich Web applications. By using ICEfaces, developers can create apps that are completely server-centric, thereby removing the need for client-side business logic and application data. Validation is also handled exclusively on the server, so there are no mismatches or inconsistencies that may open a security hole. Other strategic security advantages are also detailed.

The seven-page ICEsoft paper includes charts, point-by-point discussions of Ajax security gaps and how those challenges can be met through the JSF-ICEfaces implementation. To download the free paper, simply log on to http://www.icefaces.org/main/resources/whitepapers.iface.

About ICEsoft Technologies Inc.

ICEsoft Technologies, Inc., is a leading provider of standards-compliant, Ajax-based solutions for developing and deploying Java EE, rich Internet applications. The company's portfolio of enterprise level Java products includes ICEfaces, an Ajax application framework that enables Java EE application developers to easily create and deploy thin-client rich Web applications in pure Java. Visit www.icesoft.com or www.icefaces.org for more information.

ICEsoft and ICEfaces are registered trademarks or trade names of ICEsoft Technologies, Inc. All other company and product names may be the subject of intellectual property rights reserved by third parties.



Related Resources

Other Resources