Q: ColdFusion and ESAPI?

65 views
Skip to first unread message

Ron Stewart

unread,
Oct 11, 2011, 7:59:18 AM10/11/11
to cfe...@googlegroups.com
Not specifically related to CFESAPI project, I realize, but...

Are the existing application security tags (CFLOGIN, CFLOGOUT, CFLOGINUSER) and functions (IsAuthUser, etc.) based on ESAPI or something else?

-- 
/ron

Jason Dean

unread,
Oct 11, 2011, 11:42:36 AM10/11/11
to cfesapi
They are very simple Role-Based Authentication. As far as I know they
have been around a lot longer than ESAPI, so no.

Jason

Damon Miller

unread,
Oct 11, 2011, 11:46:51 AM10/11/11
to cfe...@googlegroups.com
Hi Ron,

I seriously doubt this.  The ESAPI.jar was just recently added to Adobe CF in a patch release in order to better secure the CFAdmin.  I do know that more ESAPI support is coming in the next version of CF "Zeus" but I don't know if that will involve changes to the functionality you mentioned.

This is just a best guess on my part.  This question would probably be much better suited for an Adobe CF evangelist.

Thanks
--
Damon M. Miller
Senior Web Application Developer / Architect



--
You received this message because you are subscribed to the Google Groups "cfesapi" group.
To view this discussion on the web visit https://groups.google.com/d/msg/cfesapi/-/aTI1AZWdBS0J.
To post to this group, send email to cfe...@googlegroups.com.
To unsubscribe from this group, send email to cfesapi+u...@googlegroups.com.
For more options, visit this group at http://groups.google.com/group/cfesapi?hl=en.

Ron Stewart

unread,
Oct 11, 2011, 6:01:15 PM10/11/11
to cfe...@googlegroups.com
Thanks, Damon and Jason.

-- 
/ron
Reply all
Reply to author
Forward
0 new messages