Sometimes people become surprisingly stupid when specifying software. I think they would probably notice their error if they asked you to build a physical safe that only required a combination if you weren't allowed to open it.
To impliment their design, you could just give everyone in the world access to the 'restricted' page without any sort of authentication challenge. You won't get caught immediately since your clients are obviously important enough to be included in the restricted group. Eventually, someone with at least a minimal level of intellegence will looks at the page and realise what you've done, at which point it becomes their problem.
no subject
2005-05-12 15:45 (UTC)To impliment their design, you could just give everyone in the world access to the 'restricted' page without any sort of authentication challenge. You won't get caught immediately since your clients are obviously important enough to be included in the restricted group. Eventually, someone with at least a minimal level of intellegence will looks at the page and realise what you've done, at which point it becomes their problem.