Solved

CFX problem

Posted on 2002-05-03
4
274 Views
Last Modified: 2013-12-24
Hi everybody,

System:
Coldfusion 5.0 (Linux)
Apache

I'm writing a CFX tag to securly retrieve passwords for our users. In order to confirm their identity i need the CFX to workout what directory the calling template is in (i have a UNIX library that uses the getUID() call) - but WITHOUT the user entering the template.

The only option i have come up with so far is using a CFML tag that uses getCurrentTemplatePath() (or whatever its called :) and then it calls the CFX. The down side of this is that you can decompile CFML tags very easily.

Points will go to the first viable solution other than the one above.

GR.
0
Comment
Question by:googlyralph
  • 2
  • 2
4 Comments
 
LVL 11

Accepted Solution

by:
jimmy282 earned 200 total points
ID: 6988736
GetDirectoryFromPath(GetTemplatePath())

You can pass the above as a parameter to the CFX from the calling page.

Or just set it as a variable in your application.cfm and you are done!

Jimmy
0
 
LVL 1

Author Comment

by:googlyralph
ID: 6993635
Jimmy,

trying to avoid passing in a parameter, as user could call the resulting CFX with a string and then retrieve another users password.

GR.
0
 
LVL 11

Expert Comment

by:jimmy282
ID: 6994502
Well thats avoidable.

1)Encrypt the parameter and Send, then decrypt in CFX.
2) Pass Another Parameter and if that is passes only then CFX will run. e.g. "Hideme=Yes"

Jimmy


0
 
LVL 1

Author Comment

by:googlyralph
ID: 7095347
Sorry for the delay, didnt realise i hadnt closed these questions.

GR.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
excpetion with multiple catch 11 113
Internal DNS Zone Issue 13 60
Connect to MS-SQL server from Linux/PHP 8 81
DNS @ Naked Domain Record 5 67
A web service (http://en.wikipedia.org/wiki/Web_service) is a software related technology that facilitates machine-to-machine interaction over a network. This article helps beginners in creating and consuming a web service using the ColdFusion Ma…
Have you ever sent email via ColdFusion and thought of tracking this mail to capture the exact date and time when the message was opened ?  If yes, then this article is for you ! First we need a table user_email with columns user_id , email , sub…
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now