Are User Authentication Server Behaviors Secure for CMS?
I am working on a small Government site and was wondering if the DW built in server behaviors are safe enough to secure a small CMS area I have built. Are there any pitfalls to the "Restrict Access to Page" or other User Authentication behaviors? Any improvements I should add? I mainly want to be sure that the area I created is only accessed by authenticated users. I have DW CS4 and also DW8 which use same structure it looks like.
I am using PHP 5.2/MySQL 5 and an SSL cert. Should I also add Windows Authentication Security to the CMS folder or anything else?
Any feedback is greatly appreciated. Thank You.
