362
Chapter 16: Securing Applications
The following table describes the CFML code in Application.cfm and its function:
.
Code
Description
<cfapplication name="Orders"
sessionmanagement="Yes"
>
loginStorage=”Session”
Identifies the application, enables the
Session scope, and enables storing login
information in the Session scope.
<cfif IsDefined("Form.logout")>
<cflogout>
</cfif>
If the user just submitted the logout form,
logs out the user. The following
cflogin
tag runs as a result.
<cflogin>
<cfif NOT IsDefined("cflogin")>
<cfinclude template="loginform.cfm">
<cfabort>
Executes if there is no logged-in user.
Tests to see if the user has submitted a
login form. If not, uses
cfinclude
to
display the form. The built-in
cflogin
variable exists and contains the user name
and password only if the login form used
j_username
and
j_password
for the
input fields.
The
cfabort
tag prevents processing of
any code that follows on this page.
<cfelse>
<cfif cflogin.name IS "" OR
cflogin.password IS "">
<cfoutput>
<H2>You must enter text in both the
User Name and Password fields</H2>
</cfoutput>
<cfinclude template="loginform.cfm">
<cfabort>
Executes if the user submitted a login
form.
Tests to make sure that both name and
password have data. If either variable is
empty, displays a message, followed by
the login form.
The
cfabort
tag prevents processing of
any code that follows on this page.
<cfelse>
<cfquery name="loginQuery"
dataSource="CompanyInfo">
SELECT UserID, Roles
FROM LoginInfo
WHERE
UserID = '#cflogin.name#'
AND Password = '#cflogin.password#'
</cfquery>
Executes if the user submitted a login form
and both fields contain data.
Uses the cflogin structure’s
name
and
password
entries to find the user record in
the database and get the user’s roles.
<cfif loginQuery.Roles NEQ "">
<cfloginuser name="#cflogin.name#"
Password = "#cflogin.password#"
roles="#loginQuery.Roles#">
If the query returns data in the Roles field,
logs in the user using the user’s name and
password and the Roles field from the
database. In this application, every user
must be in some role.
<cfelse>
<cfoutput>
<H2>Your login information is not
valid.<br>
Please Try again</H2>
</cfoutput>
<cfinclude template="loginform.cfm">
<cfabort>
Executes if the query did not return a role.
If the database is valid, this means there
was no entry matching the user ID and
password. Displays a message, followed
by the login form.
The
cfabort
tag prevents processing of
any code that follows on this page.
Содержание ColdFusion MX
Страница 1: ...Developing ColdFusion MX Applications...
Страница 22: ...22 Contents...
Страница 38: ......
Страница 52: ...52 Chapter 2 Elements of CFML...
Страница 162: ......
Страница 218: ...218 Chapter 10 Writing and Calling User Defined Functions...
Страница 250: ...250 Chapter 11 Building and Using ColdFusion Components...
Страница 264: ...264 Chapter 12 Building Custom CFXAPI Tags...
Страница 266: ......
Страница 314: ...314 Chapter 14 Handling Errors...
Страница 344: ...344 Chapter 15 Using Persistent Data and Locking...
Страница 349: ...About user security 349...
Страница 357: ...Security scenarios 357...
Страница 370: ...370 Chapter 16 Securing Applications...
Страница 388: ...388 Chapter 17 Developing Globalized Applications...
Страница 408: ...408 Chapter 18 Debugging and Troubleshooting Applications...
Страница 410: ......
Страница 426: ...426 Chapter 19 Introduction to Databases and SQL...
Страница 476: ...476 Chapter 22 Using Query of Queries...
Страница 534: ...534 Chapter 24 Building a Search Interface...
Страница 556: ...556 Chapter 25 Using Verity Search Expressions...
Страница 558: ......
Страница 582: ...582 Chapter 26 Retrieving and Formatting Data...
Страница 668: ......
Страница 734: ...734 Chapter 32 Using Web Services...
Страница 760: ...760 Chapter 33 Integrating J2EE and Java Elements in CFML Applications...
Страница 786: ...786 Chapter 34 Integrating COM and CORBA Objects in CFML Applications...
Страница 788: ......
Страница 806: ...806 Chapter 35 Sending and Receiving E Mail...