RE: Web Datablade
Posted in 2008
Topics: Java & JDBC Development
Sorry, the MISQL code would be something like this: <?misql sql="select usersec_level from user_table where user_id=$uid> $(SETVAR, $usersec,$1) <?/misql> where usersec is a variable you defined earlier, probably using MIVAR. Thanks! Veronica. From: vgomesn@hotmail.com To: kl.becker@gmx.at; informix-list@iiug.org Subject: RE: Web Datablade Date: Wed, 10 Dec 2008 22:33:25 +0000 Hi Klaus, Maybe something like this could work for you? If the users' levels are stored in a table, and you receive the user id as a variable for the web page, then maybe you could query (using MISQL tag) your users table to find out what security level the user who logged into the web application, has, and then: Based on the result of this query, you can condition (using a MIBLOCK COND and MIELSE tags) what is it to be shown after this line, in the web page. The remaining contents in the web page will vary depending on the security level of that user. For instance: - If the user can see all the contents, then put all these contents in the first block of MIBLOCK (in what would correspond to the 'THEN' block) - If the user is not supposed to see anything else, or should receive a message about his/her security level, then put this other HTML content inside what would be the MIELSE body of the MIBLOCK tag. Inside these different versions of the HTML page that you will show depending on the user level, you could include Javascript code that will be executed after the web datablade page is resolved, once the page is rendered on the client browser. An example: Something like this: <!-- query the security level of your user id and store it in a variable, let's say $usersec --> <?misql sql="select usersec_level from user_table where user_id=$uid> <?mivar name=usersec>$1<?/mivar> <?/misql> <!-- then, condition the contents of what follows in the page (which won't rollback) based on that user's security level retrieved above --> <?miblock cond="$(>=,$usersec,$minseclevel)"> here is the whole remaining HTML page if the condition is true, ie, if the user is allowed because meets your min sec level <?mielse> here is the whole remaining HTML page or error message if the condition is false... if the user is not allowed to see more contents <?/miblock> As you know, each Web Datablade page is a transaction, so it's everything in there executed, or nothing at all... That's why the other option besides a MIERROR tag (which seems that would work too) would be to condition the contents of the page inside MIBLOCK blocks, based on the result of a previous query executed using a MISQL tag. If you use the user access table (MIusertable) table in web datablade, maybe the user_level would be something to check too, as you can control access level per page and per user authenticated via NSAPI, Apache API or ISAPI drivers. Hope it helps. Veronica. > From: kl.becker@gmx.at > Subject: Web Datablade > Date: Wed, 10 Dec 2008 00:52:08 -0800 > To: informix-list@iiug.org > > Hello > > I'm new to informix web datablade programming and > needs a possibility to stop the generation of a page, > if the user has no permission for it. > Because actually it's only done by javascript, > which is not really secure. > My current solution is to throw an error at the "misql"-tag and > show the text of the "mierror"-tag, > but the problem of the way is that a rollback will be done. > > A commit in "misql"-tag hasn't work and the same in the Stored > Procedure. > > Any ideas? > > Kind Regards > klaus > > _______________________________________________ > Informix-list mailing list > Informix-list@iiug.org > http://www.iiug.org/mailman/listinfo/informix-list Color coding for safety: Windows Live Hotmail alerts you to suspicious email. Sign up today. _________________________________________________________________ Color coding for safety: Windows Live Hotmail alerts you to suspicious email. http://windowslive.com/Explore/Hotmail?ocid=TXT_TAGLM_WL_hotmail_acq_safety_112008
Hello sorry, that isn't possible, because the security check will be done in a dynamic tag, which will be used in some page also generated pages which are in the DB as BLOB: So I couldn't make a new miblock which would be the easiest way. It look likes this START of Page <?misql sql="select usersec_level from user_table where user_id= $uid> <?mivar name=usersec>$1<?/mivar> <?/misql> <?misql sql="insert some logs><?/misql> <!-- then, condition the contents of what follows in the page (which won't rollback) based on that user's security level retrieved above -- > <?miblock cond="$(<,$usersec,$minseclevel)"> here is the whole remaining HTML page or error message if the condition is false... if the user is not allowed to see more contents Javascript Alert and Javascript Close start new code <mierror> no other content will be displayed </mierror> <?misql sql="select usersec_level from doerror ><?/misql> end new code <?/miblock> CONTENT which must not be seen!!! END of Page So I need a way to commit the inserts and don't display the CONTENT if the user hasn't the permission, because javascript couldn't be a solution (old code :( ). Kind Regards klaus
You could also move the redirect to the tag that you are doing the security check in.... An example of a modification to a selectlist tag to redirect the user to another page when a value from the drop down is picked would be like this... <?MIVAR NAME=$O01><?/MIVAR> <?MIVAR> <SELECT NAME=@NAME@ $(IF,$(EQ,@SIZE@,),,SIZE=@SIZE@) $(IF,$(EQ,@MULTIPLE@,),MULTIPLE) $(IF,$(EQ,@ONCLICK@,"TRUE"), onChange="window.open(this.options[this.selectedIndex].value,'_self')")> <?/MIVAR> <?MIVAR NAME=$O00>@SELECTONE@<?/MIVAR> <?MIBLOCK COND=$(NE,$O00,)> <?MIVAR NAME=$O01>[@SELECTONE@]<?/MIVAR> <?/MIBLOCK> <?MIVAR NAME=O00>@SELECTED@<?/MIVAR> <?MIBLOCK COND=$(NE,$O00,)> <?MISQL NAME=$O01 SQL=$O00>[$1]<?/MISQL> <?/MIBLOCK> <OPTION VALUE=""> -- Pick a value from the list -- <?MISQL SQL="@SQL@"> <OPTION VALUE="?MIval=redirect_page&variable1=$2&variable2=$3" $(IF,$(POSITION,X$O01,[$1]),SELECTED)>$1 <?/MISQL> </SELECT> if you named the tage as say NEWTAG you would call it as <?NEWTAG ONCLICK=TRUE SQL="select col1,col,col2 from abc"> Thanks -Manoj beckk <kl.becker@gmx.at> Sent by: informix-list-bounces@iiug.org 12/10/2008 11:20 PM To informix-list@iiug.org cc Subject Re: Web Datablade Hello sorry, that isn't possible, because the security check will be done in a dynamic tag, which will be used in some page also generated pages which are in the DB as BLOB: So I couldn't make a new miblock which would be the easiest way. It look likes this START of Page <?misql sql="select usersec_level from user_table where user_id= $uid> <?mivar name=usersec>$1<?/mivar> <?/misql> <?misql sql="insert some logs><?/misql> <!-- then, condition the contents of what follows in the page (which won't rollback) based on that user's security level retrieved above -- > <?miblock cond="$(<,$usersec,$minseclevel)"> here is the whole remaining HTML page or error message if the condition is false... if the user is not allowed to see more contents Javascript Alert and Javascript Close start new code <mierror> no other content will be displayed </mierror> <?misql sql="select usersec_level from doerror ><?/misql> end new code <?/miblock> CONTENT which must not be seen!!! END of Page So I need a way to commit the inserts and don't display the CONTENT if the user hasn't the permission, because javascript couldn't be a solution (old code :( ). Kind Regards klaus _______________________________________________ Informix-list mailing list Informix-list@iiug.org http://www.iiug.org/mailman/listinfo/informix-list