368
Chapter 16: Securing Applications
Reviewing the code
The following table describes the code and its function. Comments and some tab characters have
been removed for brevity.
Code
Description
<cflogin>
<cfif isDefined("cflogin")>
<cfset LDAP_root = "o=mycompany.com">
<cfset LDAP_server ="ldap.mycompany.com">
<cfset LDAP_port="389">
<cfset userfilter = "(&(objectclass=*)
(uid=#cflogin.name#))">
<cfset LDAP_username = "cn=Directory
Manager">
<cfset LDAP_password = "password">
Starts the
cflogin
tag body. Sets several of
the values used as attributes in the
cfldap
tags as variables. This ensures that the same
value is used in both tags, and makes it easier
to change the settings if needed.
Sets the filter used to search the directory to
include the login name.
Sets the directory manager’s user name and
password for the first query.
<cftry>
<cfldap action="QUERY"
name="userSearch"
attributes="dn"
start="#LDAP_root#"
scope="SUBTREE"
server="#LDAP_server#"
port="#LDAP_port#"
filter="#userfilter#"
username="#LDAP_username#"
password="#LDAP_password#"
>
In a
cftry
block, uses the directory manager’s
identity to get the distinguished name (dn) for
the user. If the user ID is not in the directory,
returns an empty record set.
<cfcatch type="Any">
<cfset UserSearchFailed = true>
</cfcatch>
</cftry>
Catches any exception. Sets a
UserSearchFailed flag to True.
Ends the
cftry
block.
<cfif NOT userSearch.recordcount OR
isDefined("UserSearchFailed")>
<cfoutput>
<script> alert("UID for #cflogin.name#
not found"); </script>
</cfoutput>
<cfabort>
</cfif>
If the LDAP lookup did not return any results,
or the UserSearchFailed flag is True, displays
an error message and ends processing of the
page. Uses the JavaScript
alert
function to
display the message in a dialog box.
<cftry>
<cfldap
action="QUERY"
name="auth"
attributes="cn"
start="ou=Product Support,dc=Allaire,
dc=com"
scope="SUBTREE"
server="#LDAP_server#"
port="#LDAP_port#"
filter="(&(objectClass=groupOfUniqueNames)
(uniquemember=#userSearch.dn#))"
username="#userSearch.dn#"
password="#cflogin.password#"
>
In a
cftry
block, uses the distinguished name
from the previous query in the
username
attribute and the user-supplied password in
the
password
attribute to access the directory.
Uses the distinguished name from the
previous query in the
filter
attribute to get
the user’s roles.
If either the dn or password is invalid, the
cfldap
tag throws an error, which is caught in
the
cfcatch
block.
Содержание COLDFUSION MX 61-DEVELOPING COLDFUSION MX
Страница 1: ...Developing ColdFusion MX Applications...
Страница 22: ...22 Contents...
Страница 38: ......
Страница 52: ...52 Chapter 2 Elements of CFML...
Страница 162: ......
Страница 218: ...218 Chapter 10 Writing and Calling User Defined Functions...
Страница 250: ...250 Chapter 11 Building and Using ColdFusion Components...
Страница 264: ...264 Chapter 12 Building Custom CFXAPI Tags...
Страница 266: ......
Страница 314: ...314 Chapter 14 Handling Errors...
Страница 344: ...344 Chapter 15 Using Persistent Data and Locking...
Страница 349: ...About user security 349...
Страница 357: ...Security scenarios 357...
Страница 370: ...370 Chapter 16 Securing Applications...
Страница 388: ...388 Chapter 17 Developing Globalized Applications...
Страница 408: ...408 Chapter 18 Debugging and Troubleshooting Applications...
Страница 410: ......
Страница 426: ...426 Chapter 19 Introduction to Databases and SQL...
Страница 476: ...476 Chapter 22 Using Query of Queries...
Страница 534: ...534 Chapter 24 Building a Search Interface...
Страница 556: ...556 Chapter 25 Using Verity Search Expressions...
Страница 558: ......
Страница 582: ...582 Chapter 26 Retrieving and Formatting Data...
Страница 668: ......
Страница 734: ...734 Chapter 32 Using Web Services...
Страница 760: ...760 Chapter 33 Integrating J2EE and Java Elements in CFML Applications...
Страница 786: ...786 Chapter 34 Integrating COM and CORBA Objects in CFML Applications...
Страница 788: ......
Страница 806: ...806 Chapter 35 Sending and Receiving E Mail...