Thanks Cees. I wasn't setting the cookie. Here is the new session
checking/setting sub

sub get_session_id{
     my $self  = shift;
     my $query = $self->query;
     my $rm = $query->param('rm');

     
     # check to see if CGI.pm object has ID parammeter(from the cookie)
     my $user_id =  $query->cookie('CGISESSID') || undef;
     my $session = new CGI::Session(undef, $user_id, {Directory=>'/tmp',
expire=>'+20m'});
     unless ($user_id)     {
         $user_id = $session->id();
     }
     
     my $cookie = $query->cookie(CGISESSID => $user_id);
     $self->header_props(-cookie => $cookie,);
     return $session, $user_id;
}


 
 
>>>Cees Hek <[EMAIL PROTECTED]> 03/08 5:02 pm >>> 
On Tue, 08 Mar 2005 16:44:09 -0600, Geoffrey G. Hankerson 
<[EMAIL PROTECTED]> wrote: 
>I am trying to create an app where some pages (or run modes) are world 
>viewable while others (those that involve modifying the site) require 
>authentication. 
 
There is an Authentication plugin for CGI::Application that has been 
posted on the list if you care to look in the archives.  It currently 
requires a bit more work than you may care to do, since it requires 
you to patch CGI::Application.  If you can wait another couple of 
weeks, we may have a more complete (prepackaged) solution for this. 
 
>So my thinking was to use CGI:Session and create a subroutine or 2 to 
>check if there is a current session and if session->param('logged_in') 
>is true. If so continue to page the user requested; if not reroute to 
>login page. 
 
If you want to use CGI::Session, have a look at the 
CGI::Application::Plugin::Session module which uses CGI::Session, and 
does all the hard work for you.  Also, instead of rolling your own 
authentication code, have a loog at CGI::Session::Auth which give a 
nice framework for authentication and authorization (this is what the 
Auth plugin I mention above uses). 
 
>I have a sub called secrity_checkup which I call at the start of a run 
>mode which needs authentication. This sub calls the get_session_id
which 
>creates the session if it doesn't already exist. The problem is 
>session->param('logged_in') always evaluates to false. Where am I going

>wrong? 
 
My guess would be that you are having cookie problems.  Are you 
setting a cookie when the session is created, so that on the next 
request you know which session to use?  Otherwise you will get a new 
session every time.  Also, make sure that your session changes are 
actually being written to your data store. 
 
You might save some trouble by doing your authentication checks in the 
cgiapp_prerun method, which gets called right before your runmode gets 
called.  This means you won't have to add your bit of code to the 
beginning of each runmode. 
 
>(Please go easy on me - they made me do cut and paste data entry for a 
>year straight and I can't seem to write code anymore) 
 
That sounds painful.  Nice to hear you are moving on to more interesting
tasks. 
 
Cheers, 
 
Cees 
 
--------------------------------------------------------------------- 
Web Archive:  http://www.mail-archive.com/[email protected]/ 
             http://marc.theaimsgroup.com/?l=cgiapp&r=1&w=2 
To unsubscribe, e-mail: [EMAIL PROTECTED] 
For additional commands, e-mail: [EMAIL PROTECTED] 
 

---------------------------------------------------------------------
Web Archive:  http://www.mail-archive.com/[email protected]/
              http://marc.theaimsgroup.com/?l=cgiapp&r=1&w=2
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to