
342
DEVELOPING
COLDFUSION 9 APPLICATIONS
Developing CFML Applications
Las
t
upda
te
d 8/5/2010
The following image shows a typical flow of control for user authentication and authorization. Following sections
expand on this diagram to describe how you implement user security in ColdFusion.
Authenticating users
Use either, or both, of the following forms of authentication to secure your ColdFusion application:
•
Web server authentication, where the web server authenticates the user and does not allow access to the website by
users without valid login IDs
•
Application authentication, where the ColdFusion application authenticates the user and does not allow access to
the application by users without valid login IDs
Web server authentication
All major web servers support basic HTTP authentication. Some web servers also support other authentication
methods, including Digest HTTP authentication and Microsoft NTLM authentication.
Is a user
logged in
User requests a
page.
Display login form.
No
Use ID and password to
authenticate user and get
user's authorization roles.
Is the user
authenticated?
Log user in.
Is user in role
needed for activity?
User is authenticated and
authorized.
Do secured operations.
User is authenticated but
not authorized.
Do not do secured
operations.
Process requested page.
Yes
Yes
No
Yes
No
Содержание COLDFUSION 9
Страница 1: ...Developing Applications ADOBE COLDFUSION 9...