
Publishing web services
727
Using ColdFusion to control access
Instead of letting the web server control access to your web services, you can handle the
username/password string in your Application.cfm file as part of your own security mechanism.
In this case, you use the
cflogin
tag to retrieve the username/password information from the
authorization
header, decode the binary string, and extract the username and password, as the
following example Application.cfm file shows:
<cfsilent>
<cflogin>
<cfset isAuthorized = false>
<cfif isDefined("cflogin")
<!--- verify user name from cflogin.name and password from
cflogin.password
using your authentication mechanism --->
>
<cfset isAuthorized = true>
</cfif>
</cflogin>
<cfif not isAuthorized>
<!--- If the user does not pass a username/password, return a 401 error.
The browser then prompts the user for a username/password. --->
<cfheader statuscode="401">
<cfheader name="WWW-Authenticate" value="Basic realm=""Test""">
<cfabort>
</cfif>
</cfsilent>
This example does not show how to perform user verification. For more information on
verification, see
Chapter 16, “Securing Applications,” on page 345
.
Assigning security roles to functions
ColdFusion components offer role-based security. The following example creates a component
method that deletes files:
<cfcomponent>
<cffunction name="deleteFile" access="remote"
roles="admin,manager"
>
<cfargument name="filepath" required="yes">
<cffile action="DELETE" file=#arguments.filepath#>
</cffunction>
</cfcomponent>
In the example, the
cffunction
tag includes the
roles
attribute to specify the user roles allowed
to access it. In this example, only users in the role
admin
and
manager
can access the function.
Notice that multiple roles are delimited by a comma.
Role based security can be used with any ColdFusion component, not just for web services. For
more information on roles, see
Chapter 16, “Securing Applications,” on page 345
.
Содержание ColdFusion MX
Страница 1: ...Developing ColdFusion MX Applications...
Страница 22: ...22 Contents...
Страница 38: ......
Страница 52: ...52 Chapter 2 Elements of CFML...
Страница 162: ......
Страница 218: ...218 Chapter 10 Writing and Calling User Defined Functions...
Страница 250: ...250 Chapter 11 Building and Using ColdFusion Components...
Страница 264: ...264 Chapter 12 Building Custom CFXAPI Tags...
Страница 266: ......
Страница 314: ...314 Chapter 14 Handling Errors...
Страница 344: ...344 Chapter 15 Using Persistent Data and Locking...
Страница 349: ...About user security 349...
Страница 357: ...Security scenarios 357...
Страница 370: ...370 Chapter 16 Securing Applications...
Страница 388: ...388 Chapter 17 Developing Globalized Applications...
Страница 408: ...408 Chapter 18 Debugging and Troubleshooting Applications...
Страница 410: ......
Страница 426: ...426 Chapter 19 Introduction to Databases and SQL...
Страница 476: ...476 Chapter 22 Using Query of Queries...
Страница 534: ...534 Chapter 24 Building a Search Interface...
Страница 556: ...556 Chapter 25 Using Verity Search Expressions...
Страница 558: ......
Страница 582: ...582 Chapter 26 Retrieving and Formatting Data...
Страница 668: ......
Страница 734: ...734 Chapter 32 Using Web Services...
Страница 760: ...760 Chapter 33 Integrating J2EE and Java Elements in CFML Applications...
Страница 786: ...786 Chapter 34 Integrating COM and CORBA Objects in CFML Applications...
Страница 788: ......
Страница 806: ...806 Chapter 35 Sending and Receiving E Mail...