RE: Web Datablade
Posted in 2008
Hi Klaus, Maybe something like this could work for you? If the users' levels are stored in a table, and you receive the user id as a variable for the web page, then maybe you could query (using MISQL tag) your users table to find out what security level the user who logged into the web application, has, and then: Based on the result of this query, you can condition (using a MIBLOCK COND and MIELSE tags) what is it to be shown after this line, in the web page. The remaining contents in the web page will vary depending on the security level of that user. For instance: - If the user can see all the contents, then put all these contents in the first block of MIBLOCK (in what would correspond to the 'THEN' block) - If the user is not supposed to see anything else, or should receive a message about his/her security level, then put this other HTML content inside what would be the MIELSE body of the MIBLOCK tag. Inside these different versions of the HTML page that you will show depending on the user level, you could include Javascript code that will be executed after the web datablade page is resolved, once the page is rendered on the client browser. An example: Something like this: <!-- query the security level of your user id and store it in a variable, let's say $usersec --> <?misql sql="select usersec_level from user_table where user_id=$uid> <?mivar name=usersec>$1<?/mivar> <?/misql> <!-- then, condition the contents of what follows in the page (which won't rollback) based on that user's security level retrieved above --> <?miblock cond="$(>=,$usersec,$minseclevel)"> here is the whole remaining HTML page if the condition is true, ie, if the user is allowed because meets your min sec level <?mielse> here is the whole remaining HTML page or error message if the condition is false... if the user is not allowed to see more contents <?/miblock> As you know, each Web Datablade page is a transaction, so it's everything in there executed, or nothing at all... That's why the other option besides a MIERROR tag (which seems that would work too) would be to condition the contents of the page inside MIBLOCK blocks, based on the result of a previous query executed using a MISQL tag. If you use the user access table (MIusertable) table in web datablade, maybe the user_level would be something to check too, as you can control access level per page and per user authenticated via NSAPI, Apache API or ISAPI drivers. Hope it helps. Veronica. > From: kl.becker@gmx.at > Subject: Web Datablade > Date: Wed, 10 Dec 2008 00:52:08 -0800 > To: informix-list@iiug.org > > Hello > > I'm new to informix web datablade programming and > needs a possibility to stop the generation of a page, > if the user has no permission for it. > Because actually it's only done by javascript, > which is not really secure. > My current solution is to throw an error at the "misql"-tag and > show the text of the "mierror"-tag, > but the problem of the way is that a rollback will be done. > > A commit in "misql"-tag hasn't work and the same in the Stored > Procedure. > > Any ideas? > > Kind Regards > klaus > > _______________________________________________ > Informix-list mailing list > Informix-list@iiug.org > http://www.iiug.org/mailman/listinfo/informix-list _________________________________________________________________ Color coding for safety: Windows Live Hotmail alerts you to suspicious email. http://windowslive.com/Explore/Hotmail?ocid=TXT_TAGLM_WL_hotmail_acq_safety_112008