<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Session and Authentication Strategies in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241767#M194897</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Nicolas,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;i don't really know if this is possible, when using Alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Performing an operation is a good way, i managed it in the same way, after creating a CMIS session in my application. But the repository root is no good idea… I used the getRepositoryInfo operation, which is running good for an administrator, but not for an normal user (they are not allowed to see these information). Also the repository root is not good I think, when having users, that can just read/write their own home directory and existing sub directories.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;best regards, gclaussn&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Jun 2010 14:44:00 GMT</pubDate>
    <dc:creator>gclaussn</dc:creator>
    <dc:date>2010-06-23T14:44:00Z</dc:date>
    <item>
      <title>User Session and Authentication Strategies</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241760#M194890</link>
      <description>Hi everyone,I was just wondering this forum's thoughts about Session management and user authentication.I'm doing a Proof of Concept with Alfresco and have decided to got down the CMIS route.&amp;nbsp; So far, everything has been going well.&amp;nbsp; Now I'm to the point where I get to start messing around with diff</description>
      <pubDate>Fri, 11 Jun 2010 16:14:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241760#M194890</guid>
      <dc:creator>athrawn17</dc:creator>
      <dc:date>2010-06-11T16:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: User Session and Authentication Strategies</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241761#M194891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;As I do more investigation on this, does anyone know if the external authentication subsystem can be used with CMIS?&amp;nbsp; I'm trying to configure it now, but not having any luck yet, I have the header set and can see the value coming over, but it is still wanting a password.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jun 2010 19:12:15 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241761#M194891</guid>
      <dc:creator>athrawn17</dc:creator>
      <dc:date>2010-06-11T19:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: User Session and Authentication Strategies</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241762#M194892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;For all the pomp and circumstance around Alfresco's CMIS implementation, you are sure quiet on this forum……&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jun 2010 15:23:21 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241762#M194892</guid>
      <dc:creator>athrawn17</dc:creator>
      <dc:date>2010-06-17T15:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: User Session and Authentication Strategies</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241763#M194893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;i don't see the problem, if you have an application, which should be used by different users, you might have something like a login screen where the user is typing in a password, why not use these also for the alfresco account…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;maybe you can give me more information, what you exactly planing to do.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;best regards, gclaussn&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jun 2010 17:43:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241763#M194893</guid>
      <dc:creator>gclaussn</dc:creator>
      <dc:date>2010-06-18T17:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: User Session and Authentication Strategies</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241764#M194894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;i don't see the problem, if you have an application, which should be used by different users, you might have something like a login screen where the user is typing in a password, why not use these also for the alfresco account…&lt;BR /&gt;&lt;BR /&gt;maybe you can give me more information, what you exactly planing to do.&lt;BR /&gt;&lt;BR /&gt;best regards, gclaussn&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;In order to send the password to alfresco, we would have to store it in plain text.&amp;nbsp; This is a bad thing to do from a security perspective.&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;Our application never actually sees the password, since it is proxied to a SSO server.&amp;nbsp; We know the username as that is returned from the proxy, but never the password.&lt;/LI&gt;&lt;BR /&gt;&lt;LI&gt;We could send a token to alfresco, or use a header property to tell alfresco that the user has already been authenticated, but the CMIS implementation requires a username/password.&lt;/LI&gt;&lt;/UL&gt;&lt;SPAN&gt;And that was my original question.&amp;nbsp; When using CMIS, what Authenticaion strategies are available besides sending a username/password?&amp;nbsp; I don't see any other solutions.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jun 2010 18:33:49 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241764#M194894</guid>
      <dc:creator>athrawn17</dc:creator>
      <dc:date>2010-06-18T18:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: User Session and Authentication Strategies</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241765#M194895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I also see no other way, than plain text…&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Alfresco requires this: &lt;/SPAN&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&amp;lt;url&amp;gt;/api/login?u={username}&amp;amp;pw={password?}&amp;lt;/url&amp;gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;SPAN&gt;Maybe there is a way to customize the login strategie by replacing classes, or manipulating webscripts, but i think that's not the sense of your work.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jun 2010 06:38:49 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241765#M194895</guid>
      <dc:creator>gclaussn</dc:creator>
      <dc:date>2010-06-21T06:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: User Session and Authentication Strategies</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241766#M194896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Athrawn17,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Indeed that surprised me too, but in my &lt;/SPAN&gt;&lt;A href="http://code.google.com/p/struts2cmisexplorer/" rel="nofollow noopener noreferrer"&gt;CMIS browser&lt;/A&gt;&lt;SPAN&gt; I ended storing the username/password of the user as plain text, and sending them at each request.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Another thing that feels weird:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;In my app, the username/login success screen does not use the credentials to perform anything, so I don't know if the credentials are valid or not, until the next screen. So if I enter a wrong password, I am told "logged in" but actually an authentication error will appear later. I guess this could be fixed by performing a useless CMIS operation, for instance listing the repository root.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I believe the best solution, if possible in your environment, is to setup SSO, so that no login/password is needed at all. gclaussn, am I right on this?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Cheers!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Nicolas Raoul&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 07:16:54 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241766#M194896</guid>
      <dc:creator>nicolasraoul</dc:creator>
      <dc:date>2010-06-23T07:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: User Session and Authentication Strategies</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241767#M194897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Nicolas,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;i don't really know if this is possible, when using Alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Performing an operation is a good way, i managed it in the same way, after creating a CMIS session in my application. But the repository root is no good idea… I used the getRepositoryInfo operation, which is running good for an administrator, but not for an normal user (they are not allowed to see these information). Also the repository root is not good I think, when having users, that can just read/write their own home directory and existing sub directories.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;best regards, gclaussn&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 14:44:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/user-session-and-authentication-strategies/m-p/241767#M194897</guid>
      <dc:creator>gclaussn</dc:creator>
      <dc:date>2010-06-23T14:44:00Z</dc:date>
    </item>
  </channel>
</rss>

