Next "virtual" user group meeting scheduled - Building a Security System

My next presentation in what I am (tentatively) calling the ColdFusion Jedi User Group will be on September 27 at 6 PM Central. This is a class for beginners who know the basics of CFML, and are now looking to add basic security to your applications. So for example - you have a form to add, edit, and delete press releases for your site, but want the form to require an administrator username and password. I'll walk you through the basics of this starting from having nothing to having a simple logon system.

I'll then touch a bit on roles. By that I mean - what if you want some users to be able to add content, but not edit or delete? Or perhaps you don't want all your content writers publishing content. I'll show how you can create a basic authorization system such that only certain users have the ability to publish content.

Anyway, this is the plan. Comments and suggestions are welcome. For the fun of it, I created this seal online a few days ago. Don't consider it anything "official" - it is just for fun.

As always, you can find information about this meeting and all my other upcoming presentations on my Speaking Engagements page.

Comments

Love it.
I think in the original cf logo was an animated gif that had the lightening bolt flashing, didn't it?
# Posted By Phillip Senn | 9/5/06 11:07 AM
Yep. It just so happaned the web site had a the 'hand with lightning bolt' logo on it. I wonder if Allaire and this guy used the same clip art? :)
# Posted By Raymond Camden | 9/5/06 11:15 AM
Will you be using your old friend CFLOGIN or have you moved away from that technique :-)
# Posted By dickbob | 9/5/06 12:13 PM
I will mention cflogin by I will absolutely NOT be using it.
# Posted By Raymond Camden | 9/5/06 12:34 PM
This sounds great! I missed the last one but caught the recording. I've never used CFlogin, have done login checks based on session vairables. This will be a good oportunity to see how I should be doing things! Thanks Ray!!

Now all we need are membership cards?!? :)
http://www.owenwebs.com/downloads/cfjediusg.jpg
# Posted By Robert Owen | 9/5/06 1:01 PM
I'm just waiting for a lawsuit from Lucas. ;)
# Posted By Raymond Camden | 9/5/06 1:05 PM
I prefer the 'electric chicken' but that's been long retired.
# Posted By Gary Funk | 9/5/06 7:58 PM
Let's ask this guy if we can meet at his house.
http://www.modernhometheater.com/virtualtours/star...
Be sure to look at slide 12 and beyond!
# Posted By Phillip Senn | 9/6/06 9:24 AM
Don't you think that lightening bolt should have a red glowing end on it? I played with it a bit and made this:

http://www.dopefly.com/junk/cfjediseal.gif
PSD available.
# Posted By Nathan Strutz | 9/6/06 12:48 PM
Shouldn't we get rid of the http://www.says-it.com/seal?
# Posted By Phillip Senn | 9/6/06 1:08 PM
Done, refresh.
# Posted By Nathan Strutz | 9/6/06 1:11 PM
2 things: I don't actually like the glowing end... that's my personal pref.

Secondly, please put BACK the credit (says-it). The seal was made with their tool, and even if I don't use your version, its only fair.
# Posted By Raymond Camden | 9/6/06 1:45 PM
# Posted By Phillip Senn | 9/6/06 2:42 PM
Ray - You don't like it, i was just playing around, NP. However, the credit, once I've modified it, doesn't it belong to me? Especially for the number of things I've done with it. Furthermore, it's not a copyright, and you can freely remove it as well for your own version. If you like says-it, you can keep the http address on there, but that's your own call, there is no legal reason to do either, and it's not like my /junk/ folder gets big traffic :)

If you wanted to use some bastardization of the thing I threw together, I can take off the white paint over the says-it address, np, and do whatever ya like. Just let me know.
# Posted By Nathan Strutz | 9/6/06 5:36 PM
Well, I'm no copyright lawyer - but I'd probably err on the side of caution. :)
# Posted By Raymond Camden | 9/6/06 9:17 PM