I appreciate the explanation. If cflogin is setting its own
session variables (which I guess I could have checked myself),
then I can see why it doesn't know about a user logged in by an
independent cfloginuser.
So then my question is, why do I need cflogin? cfloginuser used
by itself will log in a user. GetAuthUser will test if a user is logged in.
Yes I've read the CF docs and see their example of using cflogin
and cfloginuse. But, a) I don't like loading up my
application.cfm with a lot of code, and b) I'm using Mach-II and
want to test for user authentication in a preEvent plugin, not in
application.cfm.
I suppose that using cfloginuser independent of cflogin, while
working today, runs the risk of breaking in a future release, but
I'd like to hear from someone familiar with the internals to know
if this is a safe (undocumented) practice (similar perhaps to the
unnamed scope in CFCs).
Thanks,
Dave Jones
NetEffect
At 10:09 AM 12/30/03 -0500, you wrote:
>This is correct, you must use the cfloginuser within the cflogin
>tag. cflogin looks for session variables it sets to determine if you have
>run the cflogin tag before. If these variables are not found then it
>executes the code withing the tag pair. You should put your cfloginuser
>tag in here.
>
>GetAuthUser() simply returns the name of the user you supplied in the
>cfloginuser tag. I use this after my <cflogin> pair to insure that a user
>really got logged in. If the user didn't get logged in then I deal with it
>there. More specifically, I use cflogin to attempt to login a user when
>they haven't logged in yet. The code within the tag will take their user
>information and validate it aginst a list of valid users and if they are
>found then execute the cfloginuser tag to do the actual login. Once the
>tag ends I make a call to GetAuthUser() to validate that I have a user name
>and continue to let the page load, otherwise I reprompt the user for their
>information.
>
>Hope that helped.
>
>Bill Grover
>Manager, Information Systems
>EU Services, Inc.
>649 N Horners Ln
>Rockville, MD 20850
>
>Phone: 301-424-3300 x3324
>Fax: 301-424-3696
>E-Mail: [EMAIL PROTECTED]
>
>At 07:33 AM 12/30/2003 -0500, you wrote:
> >You should only be using cfloginuser within cflogin tags.
> >
> >
> ><http://livedocs.macromedia.com/coldfusion/6.1/htmldocs/tags-p7
> 4.htm#wp287308>http://livedocs.macromedia.com/coldfusion/6.1/htmldocs/tags-p74.htm#wp287308
> >9
> ><http://livedocs.macromedia.com/coldfusion/6.1/htmldocs/tags-p74.htm#wp28730
> >89>
> >
> >-----Original Message-----
> >From: Dave Jones [mailto:[EMAIL PROTECTED]
> >Sent: Monday, December 29, 2003 3:23 PM
> >To: CF-Talk
> >Subject: cflogin vs. GetAuthUser
> >
> >I can use some help on understanding the relationship between
> >cflogin and GetAuthUser. I understand that cflogin is only
> >executed if there is no logged-in user. If there is no logged-in
> >user, should GetAuthUser return an empty string? Conversely, if
> >GetAuthUser contains a non-null value, does that mean cflogin
> >should not get executed?
> >
> >I'm asking because I'm encountering a situation where GetAuthUser
> >is returning a valid user, yet cflogin is still getting executed.
> >
> >Note that I am invoking cfloginuser outside of the cflogin tag.
> >It seems to be registering the user properly, but is that why
> >cflogin is not recognizing the logged-in user? If this is the
> >case, can I safely replace the cflogin tag with <cfif
> >Len(GetAuthUser()) eq 0>to test if a logged-in user exists?
> >
> >Thanks,
> >Dave Jones
> >NetEffect
> > _____
> >
> >----------
> >[
>
>----------
>[
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

