Security
Overview
The concept of security has been taken into serious consideration when designing the Lexden Cricket Club website. The security can be broken down into various categories:
Security Level – The different access rights a user can be granted.
Registration and Login – Securing the website by forcing registration and login.
Forum Access – Protecting the forum from random spamming with login function.
Administration – Restricting the modification of various aspects of the website by only allowing specific users to see specific areas of the administration section.

SECURITY LEVEL
If you do not have a user account then you are considered to be a ‘Guest’ and will only be able to read information on the website and not interact with it.

As soon as you register you will be automatically granted the most basic level of security permissions classed as ‘Member’ rights. This allows you to have a space in the ‘Members Area’ and the ability to add topics and reply to messages on the forum.

If required an adminstrator can upgrade your account to either a ‘Contributor’, ‘Moderator’, ‘Author’ or ‘Administrator’ depending on what it is you will be doing on the website. These security levels each refer to which areas of the administration section you will be allowed access to and which will not be displayed. elow is a table of the different security levels and their access permissions:

Security LevelAccess Permissions
GuestNone
MemberForum and Members Area
ContributorSame as Member but with the ‘Results’, ‘Reports’, ‘News’ and ‘Images’ functions under ‘Manage Data’ in Administration.
AuthorSame as Contributor but has full access to ‘Manage Data’ and ‘Amend Pages’ in Administration with the ‘Newsletter’ feature in ‘User Management’ aswell.
ModeratorSame as Member but with ‘User Management’ (except ‘Newsletter’) and ‘Forum Management’ in Administration.
AdministratorHas full access to the website and Administration including ‘Help Centre’ and ‘Website Maintenance’.

These security levels feature in many areas of the website and users should at least be aware of their own security level and what it allows them to access.

REGISTRATION AND LOGIN
The procedure of Registering with the website improves security by forcing a visitor to the website to commit their contact details the system database. Therefore if they are found to be responsible for abuse, vandalism or illegal activity they can be tracked and/or removed from the website permanently.

Logging in to the website ensures that access to more sensitive parts of the website can be protected against roaming visitors and that only members who have registered and had their account upgraded, can make any changes or interact.

The logging in process makes use of internet browser security features such as ‘Cookies’. These are small pieces of data that contain information regarding users and the website. This is different for every website and in the case of the the Lexden Cricket Club website contains information such as log in name and access level.

These cookies are linked with features such as the ‘Re-Login’ function that comes in to effect when a user has logged in to the website, closed the browser window and then come back to the website again. It is designed to prevent a user from leaving their account logged in and closing the window, then another user navigates to the website and finds the account already logged in giving them full access. This could be potentially dangerous for the website and so this extra layer of security helps prevent loss of service to other user.

FORUM ACCESS
The simple process of registering with the website gives a new user basic ‘Member’ permissions. This allows them access to the forum so that they can add a new topic or reply to an existing topic or post.

Users who have this level of access to the forum can edit or delete their own posts and topics but not those that have been added by other users. Users that have been upgraded to ‘Moderator’ or ‘Administrator’ will be able to make changes or delete any post or topic on the forum, regardless of who added them in the first place.

ADMINISTRATION
The reasons for requiring strict security to the Administration side of the website should be apparent. It could be potentially very damaging to the website for any guest to the website, or even Members, to have full access to functions that fundamentally alter the layout of pages and the information displayed. This should only be able to be carried out by users who are responsible, have the competence to complete the tasks successfully and who are interested in the well being of the club and therefore the website.

Refer to ‘Security Levels’ earlier in this document to see the various access to the website that each level provides and for more details on the various sections of the Administration side to the website please browse the Help Centre.
© 2006 - 2010 Lexden Cricket Club. All Photography, images and text are protected
by the laws of copyright and violators are subject to prosecution at the discretion
of the owners of the Lexden Cricket Club website.
Designed and Developed by T. Morgan - May 2006 - February 2007.