I have two php scripts already build , and i am pl...
# cfml-general
g
I have two php scripts already build , and i am planning to use those instead of building new modules of same functionality, my concern is has anyone done the login connection between php and coldfusion, like i login with coldfusion adn want that sessions to be avlailble for PHP to use, i want to skip the login check of php page if those session exists, has anyone done it, and is there an easy way to do, i do have some scripts, i want suggestions and if someone has done it, i need to know how, please guide
m
I did something similar to this but not between php and ColdFusion but it was between Tango (formerly owned by Pervasive Software; I believe it is called WiTango and owned by Wi Enterprise now??) and ColdFusion and changed from ColdFusion to ColdFusion but two CF sites were on two different servers (one was on-site owned by my former employer and one was owned by the marketing firm working for us). Please keep in mind that this solution was done back in year 1999/2000; the solution now may have more options. Anyway, in my case, both sites have access to the same database. When a person logs in, we would generate a token and store it in the database. This token had the login time and some information that we wanted to track. When a user left the Tango site and went to the CF side (and vice versa) by clicking a link, we would attach the token to the URL. The receiving end gets the token, would retrieve the information, delete the token, and generate a new one. This theoretically should take seconds. So, if this guy were to copy the link and sent it to his buddies, the token would not be valid anymore. The receiving end would check the information retrieved from the token. If the token does not exist or if the last active time had passed the session limit (20 minutes), we would kick the user back to the login (in my case, the login page resided on the Tango side). If a user stays on either the CF side the whole time or the Tango side the whole time, the token would never be visible. We had a scheduled task set up to remove the tokens from the database after a set amount of time.
q
@gsr -- PHP and ColdFusion cannot share sessions directly. You would have to build some sort of bridge between them -- most likely using a REST endpoint or somehow share data via a database. In theory, you could share cookies, but it will take quite a bit of work to have PHP decipher the CF cookie, talk to it's active session, and pull the login data.
a
want that sessions to be avlailble for PHP to use
To share data you have in your CF session scope with another application would require you to store your session data in something like Redis and then get ColdFusion / PHP / Ruby or whatever to get the data from Redis. This is far from simple though.
login connection between php and coldfusion
This is different to sharing session data. It can be as simple as doing a
cfhttp
request to literally pass across the username and password to any other system's login page when you login to your ColdFusion application. I do not recommend this though - and if the other system is built with any kind of security in mind it will require a CSRF token so that will fail immediately. Assuming weak security, then that will log you into both applications but still won't share data. You can only do it at login as that's the only time you'll have a plain text password (as the user typed it in). It is not a great solution so I wouldn't recommend it at all though, but your question is vague as to what you are hoping to achieve. Oh and never send username / password as a GET request (just to be clear - I do not recommend this approach, just mentioning so that you understand the pitfalls)
If systems (again this is not a ColdFusion issue) need to be able to communicate with each other then building an API using access tokens is the most common solution to this.
g
Two Options One using the api and another using the database to connect