- Joined
- Jan 12, 2023
- Messages
- 43
- Reaction score
- 13
Hello,
i'm wondering about information or inputs about how to implement most securely possible the 3CX webclient/PWA and SMartphone App.
doing some setups for customers, i come always to same conclusion, to use an 3CX app, a user need to know the URL, the username and the password. and that's it.
If someone get this infos, by intercepting the welcome e-mail for example, then any user can log in simultaneously as the real user.
URL used for webclient is the same as used for the remote management, with the difference that for Management we can set an IP blacklist, what we can't for webclient.
Same for smartphone app, with the QR code, several smartphones can be logged in at same time.
So my question is how can i secure it at maximum?
is there a function on 3CX management console, to say, like, this app has been deployed, don't accept any new deployement or something like that?
Thnaks for your feed-backs and sharing experiences.
BR
i'm wondering about information or inputs about how to implement most securely possible the 3CX webclient/PWA and SMartphone App.
doing some setups for customers, i come always to same conclusion, to use an 3CX app, a user need to know the URL, the username and the password. and that's it.
If someone get this infos, by intercepting the welcome e-mail for example, then any user can log in simultaneously as the real user.
URL used for webclient is the same as used for the remote management, with the difference that for Management we can set an IP blacklist, what we can't for webclient.
Same for smartphone app, with the QR code, several smartphones can be logged in at same time.
So my question is how can i secure it at maximum?
is there a function on 3CX management console, to say, like, this app has been deployed, don't accept any new deployement or something like that?
Thnaks for your feed-backs and sharing experiences.
BR