# CGI Security

**URL:** <https://forums.digi.com/t/cgi-security/5864>\
**Category:** NET+OS\
**Created:** [November 26, 2010, 7:57am UTC](https://forums.digi.com/t/cgi-security/5864 "2010-11-26T07:57:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rdeabill](https://avatars.discourse-cdn.com/v4/letter/r/91b2a8/32.png) [@rdeabill](https://forums.digi.com/u/rdeabill)\
**Post date:** [November 26, 2010, 7:57am UTC](https://forums.digi.com/t/cgi-security/5864/1 "2010-11-26T07:57:01Z")

</div>

Hi All,

I have recently been working with the CGI interface, but am getting a bit confused regarding security.

I have been trying to use the following  
while (naCgiCheckAccess(theDataPtr, theCgiPtr, NASYSACC\_LEVEL\_HTTP\_R1) == eRpPasswordPending) {  
printf(PWD\_FMT, tx\_time\_get());  
tx\_thread\_sleep(5);  
}

```
if (naCgiCheckAccess(theDataPtr, theCgiPtr, NASYSACC_LEVEL_HTTP_R1) == eRpPasswordAuthorized) {
	ProcessCgi(theDataPtr, theCgiPtr);
}
else {
	theCgiPtr-&gt;fHttpResponse = eRpCgiHttpUnauthorized;	
} 

```

but this seems to give some peculiar results and at times allows access even with incorrect passwords.  
Does anyone have any ideas on the correct algorithm to use or any sample code that they can share?

---

<div class="post-metadata">

**Author:** ![bert](https://avatars.discourse-cdn.com/v4/letter/b/9e8a1a/32.png) [@bert](https://forums.digi.com/u/bert)\
**Post date:** [April 29, 2016, 12:10pm UTC](https://forums.digi.com/t/cgi-security/5864/2 "2016-04-29T12:10:28Z")

</div>

Have you use the function naCgiSetAccess?  
You have to call this function for each request in RpExternalCgi,
