364
Chapter 16: Securing Applications
Reviewing the code
The following table describes the loginform.cfm page CFML code and its function:
Example: securitytest.cfm
The securitytest.cfm page shows how any application page can use ColdFusion user authorization
features. Application.cfm ensures the existence of an authenticated user before the page content
appears. The securitytest.cfm page uses the
IsUserInRole
and
GetAuthUser
functions to control
the information that is displayed.
The securitytest.cfm page consists of the following:
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>Security test page</title>
</head>
<body>
<cfoutput>
<h2>Welcome #GetAuthUser()#!</h2>
</cfoutput>
ALL Logged-in Users see this message.<br>
<br>
<cfscript>
if (IsUserInRole("Human Resources"))
WriteOutput("Human Resources members see this message.<br><br>");
if (IsUserInRole("Documentation"))
WriteOutput("Documentation members see this message.<br><br>");
if (IsUserInRole("Sales"))
WriteOutput("Sales members see this message.<br><br>");
if (IsUserInRole("Manager"))
WriteOutput("Managers see this message.<br><br>");
if (IsUserInRole("Employee"))
WriteOutput("Employees see this message.<br><br>");
Code
Description
<H2>Please Log In</H2>
<cfoutput>
<form
action="#CGI.script_name#?#CGI.
query_string#"
method="Post">
<table>
<tr>
<td>username:</td>
<td><input type="text"
name="j_username"></td>
</tr>
<tr>
<td>password:</td>
<td><input type="password"
name="j_password"></td>
</tr>
</table>
<br>
<input type="submit" value="Login">
</form>
</cfoutput>
Displays the login form.
Constructs the form
action
attribute from CGI
variables, with a ? character preceding the query
string variable. This technique works because
loginform.cfm is accessed by a
cfinclude
tag on
Application.cfm, so the CGI variables are those
for the originally requested page.
The form requests a user ID and password and
posts the user’s input to the page specified by
the newurl variable.
Uses the field names j_username and
j_password. ColdFusion automatically puts form
fields with these values in the cflogin.name and
cflogin.password variables inside the
cflogin
tag.
Содержание COLDFUSION MX 61-DEVELOPING COLDFUSION MX
Страница 1: ...Developing ColdFusion MX Applications...
Страница 22: ...22 Contents...
Страница 38: ......
Страница 52: ...52 Chapter 2 Elements of CFML...
Страница 162: ......
Страница 218: ...218 Chapter 10 Writing and Calling User Defined Functions...
Страница 250: ...250 Chapter 11 Building and Using ColdFusion Components...
Страница 264: ...264 Chapter 12 Building Custom CFXAPI Tags...
Страница 266: ......
Страница 314: ...314 Chapter 14 Handling Errors...
Страница 344: ...344 Chapter 15 Using Persistent Data and Locking...
Страница 349: ...About user security 349...
Страница 357: ...Security scenarios 357...
Страница 370: ...370 Chapter 16 Securing Applications...
Страница 388: ...388 Chapter 17 Developing Globalized Applications...
Страница 408: ...408 Chapter 18 Debugging and Troubleshooting Applications...
Страница 410: ......
Страница 426: ...426 Chapter 19 Introduction to Databases and SQL...
Страница 476: ...476 Chapter 22 Using Query of Queries...
Страница 534: ...534 Chapter 24 Building a Search Interface...
Страница 556: ...556 Chapter 25 Using Verity Search Expressions...
Страница 558: ......
Страница 582: ...582 Chapter 26 Retrieving and Formatting Data...
Страница 668: ......
Страница 734: ...734 Chapter 32 Using Web Services...
Страница 760: ...760 Chapter 33 Integrating J2EE and Java Elements in CFML Applications...
Страница 786: ...786 Chapter 34 Integrating COM and CORBA Objects in CFML Applications...
Страница 788: ......
Страница 806: ...806 Chapter 35 Sending and Receiving E Mail...