Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
How to check to see if a user is logged in
Bowker
I've written a perl script to display jobs that are assigned to the current user (checked the cookie iw_user). That script is stored in <iw-home>/httpd/iw-bin.
While testing, I signed out of teamsite to see what error I would get when I try to access this script. NONE. It ran just fine and returned all my jobs. I checked the cookie and found that iw_user was still there, but IWAUTH was gone.
My problem is, I want to make sure that before this script outputs anything, it checks to see if the user is signed in to teamsite. How can I tell if the current machine is signed on as a valid user.
Just checking for the existence of IWAUTH is no good, since anyone can create a cookie by that name.
Is there a perl package, clt... to check?
Find more posts tagged with
Comments
james1
Instead of using /iw-bin/your-script.cgi as your HTML FORM ACTION, use /iw-bin/iw_cgi_wrapper.cgi/your-script.cgi.
Note that as a side effect of this, "your-script.cgi" will now run as the logged in user, not as iwui (the user that iw-webd runs as).
-- James
Bowker
I changed it to be /iw-bin/iw_cgi_wrapper.cgi/contentManagement_dashboard_joblisting.ipl
An alert pops up with:
Teamsite : Wrapper
Error: Did not get the the session string.
(yes there are two "the"s in the error message)
james1
Oh sorry -- I had assumed that you set up this CGI as a custom menu item. That error message sounds like you are not. In that case, you probably can't use iw_cgi_wrapper.cgi, unless you feed it several more CGI variables, which may or may not be documented. (Sorry, I don't have a set of 5.5.2 manuals handy where I am right now.)
Duh, if it was a custom menu item, they would probably already be logged in to WebDesk. ;-) Sorry for not thinking all the way through.
If you don't want to make your CGI a custom menu item, then I think that you can use the value of the IWAUTH cookie as a session string in the iwprop and iwuser CLT's. I would assume that giving them a bogus session string would cause an error. So you could run a trivial command with the CLT's and make sure that the command does not cause an error to be raised.
This should help you make sure that your CGI's users aren't faking IWAUTH cookies.
-- James
iwovGraduate
I have a similar situation where I need to know (in my CGI script) if a user is already logged in.
At first I thought that just checking for a *valid* IWAUTH session string would be enough. But sometimes (this does not always happen) I notice that even when I have a valid session string (checked by "iwuser -q -user $sessionstring" or "iwprop -session $sessionstring" ) TS will prompt for login when my script tries to redirect to open a file in a workarea.
So it seems that IWAUTH cookie is present but maybe its expired ? Given the session string how do I know if the user's session is not expired ?
The information I get from iwuser or iwprop CLTs show information such as iw_area, iw_current_webdesk_command, iw_filesys_path, iw_which_ui, etc. etc. but nothing that indicates if session is expired.
I am lookinig for something like is_valid_session=[true|false]. Is there ? Any other ideas way ?
TS 5.5.2;W2k