RE: Web Datablade
Posted in 2008
Topics: Stored Procedures & SPL, Error Codes & Troubleshooting, Java & JDBC Development
Hi, To complement the option that Manoj just gave, I just wanted to add something, if it's of any help: I think that, even if you have a security check/query to be performed in a dynamic tag called in this page, you could still use this dynamic tag to query the security level of the user and to save this security level in a variable (ex: usersec). Then, you put this dynamic tag in your page(s). One page where you place this dynamic tag can then use this variable to condition or change the contents to be displayed based on the security level of the user. I would not use MIERROR in this case (because we don't have a situation in which WebExplode or the page generation will fail and you want to prevent Informix-based error messages and do something else). You could use MIERROR if you want to create and raise your own error code and handler based on the security level of the user, but it doesn't seem like it. The thing is: It doesn't look like you want to raise an error, because you want parts of the page to be done fine (like the insert), and some other parts to be done differently (ie, display different contents within the same web page, or display/redirect to different web pages), based on the security level of you user. It looks like one or several MIBLOCK's (and MIELSE, because we have two paths or behaviors on the page) would work, to put the right code to be displayed on the page based on the security level of the user or to redirect to the right page based on that security level value (having the security level been stored in a variable by a dynamic tag placed in the page). If you want your user-defined dynamic tag to do more than just query the security level and place it in a variable, remember that it has to be something generic enough and reusable across the several pages where you plan to put it. The idea of the user-defined tags are to reuse Web Datablade's segments of code, simplify the code of the pages and improve maintenance. So, I'd suggest to leave in the dynamic tag whatever is generic, and leave the pages whatever is specific to them (like customizing the contents based on a condition). Hope it helps. Regards, Veronica. To: kl.becker@gmx.at Subject: Re: Web Datablade From: mvakeel@us.ibm.com Date: Thu, 11 Dec 2008 11:41:45 -0600 CC: informix-list-bounces@iiug.org; informix-list@iiug.org You could also move the redirect to the tag that you are doing the security check in.... An example of a modification to a selectlist tag to redirect the user to another page when a value from the drop down is picked would be like this... <?MIVAR NAME=$O01><?/MIVAR> <?MIVAR> <SELECT NAME=@NAME@ $(IF,$(EQ,@SIZE@,),,SIZE=@SIZE@) $(IF,$(EQ,@MULTIPLE@,),MULTIPLE) $(IF,$(EQ,@ONCLICK@,"TRUE"), onChange="window.open(this.options[this.selectedIndex].value,'_self')")> <?/MIVAR> <?MIVAR NAME=$O00>@SELECTONE@<?/MIVAR> <?MIBLOCK COND=$(NE,$O00,)> <?MIVAR NAME=$O01>[@SELECTONE@]<?/MIVAR> <?/MIBLOCK> <?MIVAR NAME=O00>@SELECTED@<?/MIVAR> <?MIBLOCK COND=$(NE,$O00,)> <?MISQL NAME=$O01 SQL=$O00>[$1]<?/MISQL> <?/MIBLOCK> <OPTION VALUE=""> -- Pick a value from the list -- <?MISQL SQL="@SQL@"> <OPTION VALUE="?MIval=redirect_page&variable1=$2&variable2=$3" $(IF,$(POSITION,X$O01,[$1]),SELECTED)>$1 <?/MISQL> </SELECT> if you named the tage as say NEWTAG you would call it as <?NEWTAG ONCLICK=TRUE SQL="select col1,col,col2 from abc"> Thanks -Manoj beckk <kl.becker@gmx.at> Sent by: informix-list-bounces@iiug.org 12/10/2008 11:20 PM To informix-list@iiug.org cc Subject Re: Web Datablade Hello sorry, that isn't possible, because the security check will be done in a dynamic tag, which will be used in some page also generated pages which are in the DB as BLOB: So I couldn't make a new miblock which would be the easiest way. It look likes this START of Page <?misql sql="select usersec_level from user_table where user_id= $uid> <?mivar name=usersec>$1<?/mivar> <?/misql> <?misql sql="insert some logs><?/misql> <!-- then, condition the contents of what follows in the page (which won't rollback) based on that user's security level retrieved above -- > <?miblock cond="$(<,$usersec,$minseclevel)"> here is the whole remaining HTML page or error message if the condition is false... if the user is not allowed to see more contents Javascript Alert and Javascript Close start new code <mierror> no other content will be displayed </mierror> <?misql sql="select usersec_level from doerror ><?/misql> end new code <?/miblock> CONTENT which must not be seen!!! END of Page So I need a way to commit the inserts and don't display the CONTENT if the user hasn't the permission, because javascript couldn't be a solution (old code :( ). Kind Regards klaus _______________________________________________ Informix-list mailing list Informix-list@iiug.org http://www.iiug.org/mailman/listinfo/informix-list _________________________________________________________________ Windows Live Hotmail now works up to 70% faster. http://windowslive.com/Explore/Hotmail?ocid=TXT_TAGLM_WL_hotmail_acq_faster_112008
Hello the main problem is, that thousand pages allready generated in the database, so I could only easy change the code of the dynamic tag. So how can I make a redirect on server side (in my dynamic tag)? In Java I could make it in this way => response.sendRedirect (redirectURL); And an explicit sql commit isn't possible? Kind Regards klaus
Klaus,
We are using web datablade and when we need to change many pages we unload
the pages and apply a regular expression to edit that pages and load
the pages in the database.
-- script to create the project structure in the file system
unload to 'ADDW/a.bat'
select 'mkdir ' || project FROM wbresprojects group by project ;
-- script to unload all the pages (you can apply any filter)
unload to 'ADDW/pages.sql'
SELECT "SELECT HTMLTOFILE('" || pr.project ||
"\\" || pag.id || "." ||
pag.extension || "', object ) FROM wbpages WHERE id = '" ||
pag.id || "' AND extension = '" || pag.extension ||
"';"
FROM wbpages pag, wbresprojects pr WHERE pr.id = pag.id AND (
pag.extension = 'html' OR pag.extension = 'js' OR
pag.extension = 'txt' OR pag.extension = 'css' );
Run the first script and the run the second script
You will have all the desired pages in the file system
After executing the changes
you can run the followig script for each page:
-- delete the main page
delete from wbpages where id = 'empty' AND extension = 'html';
-- delete the versioned page
delete from wbpageversions where id = 'empty' AND extension = 'html';
-- insert the new page
INSERT INTO wbpages VALUES ( 'empty', '/', 'html', 'mxp', 'mxp', '', 0,
CURRENT, '', 0, CURRENT, '', filetohtml('./mediaxp_admin/empty.html' ));
Kind Regards.
Fabio
--
> Hello
>
> the main problem is, that thousand pages allready generated in the
> database,
> so I could only easy change the code of the dynamic tag.
>
> So how can I make a redirect on server side (in my dynamic tag)?
> In Java I could make it in this way => response.sendRedirect
> (redirectURL);
>
> And an explicit sql commit isn't possible?
>
> Kind Regards
> klaus
> _______________________________________________
> Informix-list mailing list
> Informix-list@iiug.org
> http://www.iiug.org/mailman/listinfo/informix-list
>