I also figured out a way to use cflogin with Mach-II. The
conceptual breakthru for me was realizing that cflogin could be
used in multiple places, sometimes w/o cfloginuser.
What I've done is place a cflogin in preEvent in my plugin. If a
user is not logged in, cflogin aborts the current event and
announces a login event (which forces display of the login page).
When the login page is submitted, a validate function in a login
bean is invoked. If the user is validated, another cflogin calls cfloginuser.
This seems pretty clean and doesn't bend the framework, so I'm
happy with it, at least for now.
Thanks for your suggestions. Collectively, everyone's
contributions got me thinking in the right direction.
Dave Jones
NetEffect
At 12:20 PM 12/31/03 +1100, you wrote:
>Dave,
>
>
>I have what your looking for working in a Mach-II application, I had to hack
>at Mach-II though. I actually use the check just before the hanlde request
>in the mach-II framework. This was my only option to handle login using my
>setup, and maybe a lack of knowing how the plugin option actually works.
>
>
>But you don't need to have cflogin to use cfloginuser, but it helps as Dave
>Watts explained. In my case I handle my own tracking and just use the
>GetAuthUser to test a users rights.
>
>Regards
>Andrew Scott
>Technical Consultant
>
>NuSphere Pty Ltd
>Level 2/33 Bank Street
>South Melbourne, Victoria, 3205
>
>Phone: 03 9686 0485 - Fax: 03 9699 7976
>
> _____
>
>From: Dave Jones [mailto:[EMAIL PROTECTED]
>Sent: Wednesday, 31 December 2003 3:39 AM
>To: CF-Talk
>Subject: RE: cflogin vs. GetAuthUser
>
>Bill,
>I appreciate the explanation. If cflogin is setting its own
>session variables (which I guess I could have checked myself),
>then I can see why it doesn't know about a user logged in by an
>independent cfloginuser.
>
>So then my question is, why do I need cflogin? cfloginuser used
>by itself will log in a user. GetAuthUser will test if a user is logged in.
>
>Yes I've read the CF docs and see their example of using cflogin
>and cfloginuse. But, a) I don't like loading up my
>application.cfm with a lot of code, and b) I'm using Mach-II and
>want to test for user authentication in a preEvent plugin, not in
>application.cfm.
>
>I suppose that using cfloginuser independent of cflogin, while
>working today, runs the risk of breaking in a future release, but
>I'd like to hear from someone familiar with the internals to know
>if this is a safe (undocumented) practice (similar perhaps to the
>unnamed scope in CFCs).
>
>Thanks,
>Dave Jones
>NetEffect
>
>At 10:09 AM 12/30/03 -0500, you wrote:
> >This is correct, you must use the cfloginuser within the cflogin
> >tag. cflogin looks for session variables it sets to determine if you have
> >run the cflogin tag before. If these variables are not found then it
> >executes the code withing the tag pair. You should put your cfloginuser
> >tag in here.
> >
> >GetAuthUser() simply returns the name of the user you supplied in the
> >cfloginuser tag. I use this after my <cflogin> pair to insure that a user
> >really got logged in. If the user didn't get logged in then I deal with it
> >there. More specifically, I use cflogin to attempt to login a user when
> >they haven't logged in yet. The code within the tag will take their user
> >information and validate it aginst a list of valid users and if they are
> >found then execute the cfloginuser tag to do the actual login. Once the
> >tag ends I make a call to GetAuthUser() to validate that I have a user name
> >and continue to let the page load, otherwise I reprompt the user for their
> >information.
> >
> >Hope that helped.
> >
> >Bill Grover
> >Manager, Information Systems
> >EU Services, Inc.
> >649 N Horners Ln
> >Rockville, MD 20850
> >
> >Phone: 301-424-3300 x3324
> >Fax: 301-424-3696
> >E-Mail: [EMAIL PROTECTED]
> >
> >At 07:33 AM 12/30/2003 -0500, you wrote:
> > >You should only be using cfloginuser within cflogin tags.
> > >
> > >
> > ><http://livedocs.macromedia.com/coldfusion/6.1/htmldocs/tags-p7
> >
>4.htm#wp287308>http://livedocs.macromedia.com/coldfusion/6.1/htmldocs/tags-p
>74.htm#wp287308
> > >9
> >
> ><http://livedocs.macromedia.com/coldfusion/6.1/htmldocs/tags-p74.htm#wp2873
>0
> > >89>
> > >
> > >-----Original Message-----
> > >From: Dave Jones [mailto:[EMAIL PROTECTED]
> > >Sent: Monday, December 29, 2003 3:23 PM
> > >To: CF-Talk
> > >Subject: cflogin vs. GetAuthUser
> > >
> > >I can use some help on understanding the relationship between
> > >cflogin and GetAuthUser. I understand that cflogin is only
> > >executed if there is no logged-in user. If there is no logged-in
> > >user, should GetAuthUser return an empty string? Conversely, if
> > >GetAuthUser contains a non-null value, does that mean cflogin
> > >should not get executed?
> > >
> > >I'm asking because I'm encountering a situation where GetAuthUser
> > >is returning a valid user, yet cflogin is still getting executed.
> > >
> > >Note that I am invoking cfloginuser outside of the cflogin tag.
> > >It seems to be registering the user properly, but is that why
> > >cflogin is not recognizing the logged-in user? If this is the
> > >case, can I safely replace the cflogin tag with <cfif
> > >Len(GetAuthUser()) eq 0>to test if a logged-in user exists?
> > >
> > >Thanks,
> > >Dave Jones
> > >NetEffect
> > > _____
> > >
> > >----------
> > >[
> >
> >----------
> >[
> _____
>
>----------
>[
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

