I am trying to create an app where some pages (or run modes) are world
viewable while others (those that involve modifying the site) require
authentication.

So my thinking was to use CGI:Session and create a subroutine or 2 to
check if there is a current session and if session->param('logged_in')
is true. If so continue to page the user requested; if not reroute to
login page. 

I have a sub called secrity_checkup which I call at the start of a run
mode which needs authentication. This sub calls the get_session_id which
creates the session if it doesn't already exist. The problem is
session->param('logged_in') always evaluates to false. Where am I going
wrong?

(Please go easy on me - they made me do cut and paste data entry for a
year straight and I can't seem to write code anymore)





package MinimalApp;
use base 'CGI::Application';
use strict;

use HTML::Template;
use CGI::Session qw\-ip-match\;

sub setup {
    my $self = shift;
    $self->start_mode('1');
    # index page is viewable to all, page1 shold require authentication
    $self->run_modes(
        '1' => 'index',
        '2' => 'page1',
        '3' => 'logout',
        '4' => 'login_form',
        '5' => 'do_login'
    );

    $self->tmpl_path("/Library/Webserver/Documents/tmpls/test/");
}


sub security_check {
     my $self = shift; 
     my $query = shift;
     
     # get session object and ID
     my ($session, $session_id) = $self->get_session_id($self, $query);
     
     # check to see if they are logged in 
     unless  ($session->param("logged_in"))     {
         return 0;
     }
     else {
         return 1; #return true if user has already logged in
     }

}


sub get_session_id{
     my ($self, $query) = @_;
     # check to see if CGI.pm object has ID parammeter(from the cookie)
     my $user_id =  $query->param('ID') || undef;
     my $session = new CGI::Session(undef, $user_id, {Directory=>'/tmp',
expire=>'+20m'});
     unless ($user_id)     {
         $user_id = $session->id();
     }
     return $session, $user_id;
}



sub logout{
    my $self = shift;
    my $session = $self->param('session');
    $session->clear('profile');
    $session->clear('logged_in');
    return $self->index();
}
    
sub processtmpl{
# processes the template with parameters gathered from the application
object
    my ($self,$tmplname) = @_;
    my $query = $self->query();
    my $template = $self->load_tmpl($tmplname, loop_context_vars => 1,);
    #my $tmplpar = $self->param('tmplpar') || {};
    #$template->param(PROFILE => $self->session->param("profile"));
    $template->param(BADLOGINS => $self->session->param("badlogins"));
    $template->param(MYURL => $query->url());
    my $html = $template->output;
    return $html;
}

sub login_form{
    my $self = shift;
    my $query = shift;
    my $template = $self->load_tmpl('login.tmpl', loop_context_vars =>
1,);
    $template->param(PAGE => '2');
    my $html = $template->output;
    return $html;
}
sub index{
    my $self = shift;
    my $template = $self->load_tmpl('index.tmpl', loop_context_vars =>
1,);
    my $html = $template->output;
    return $html;
}

sub page1{
    my $self = shift;
    my $query = $self->query;
    if (security_check($self, $query))      {
        my $template = $self->load_tmpl('page1.tmpl', loop_context_vars
=> 1,);
        my $html = $template->output;
        return $html;
    }
    else {
            $self->login_form($self, $query);
        }
    
    
    
}

sub do_login{
    #check uname and password
    my $self = shift;
    my $query = $self->query(); #CGI.pm object
    my $username = $query->param('uname');
    my $password = $query->param('pass');  
    # replace this with real authentication
    if ($username==$password){
        my ($session, $session_id) = $self->get_session_id($self,
$query);
        #die "The user has logged in. Session-logged_in value is:
$session->param('logged_in')";
        $session->param("logged_in", 1)
    }
    my $runmode = $query->param('page');
    return $self->page1;

}

1;    # Perl requires this at the end of all modules

---------------------------------------------------------------------
Web Archive:  http://www.mail-archive.com/[email protected]/
              http://marc.theaimsgroup.com/?l=cgiapp&r=1&w=2
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to