Create and deliver personalized experiences across digital properties at scale
Build engaging websites with intuitive web content management
Leverage a complete UI toolbox for web, mobile and desktop development
Build, protect and deploy apps across any platform and mobile device
Build mobile apps for iOS, Android and Windows Phone
Rapidly develop, manage and deploy business apps, delivered as SaaS in the cloud
Automate UI, load and performance testing for web, desktop and mobile
Host, deploy and scale Node.js, Java and .NET Core apps on premise or in the cloud
Optimize data integration with high-performance connectivity
Automate decision processes with a no-code business rules engine
Globally scale websites with innovative content management and infrastructure approaches
Content-focused web and mobile solution for empowering marketers
Faster, tailored mobile experiences for any device and data source
UX and app modernization to powerfully navigate today's digital landscape
Fuel agility with ever-ready applications, built in the cloud
The latest release of the OpenEdge application development and deployment platform, version 11.1, reinforces our commitment to our customers’ needs for security, privacy and compliance. OpenEdge 11.1 includes security enhancements that simplify user authentication and centralized controls.
One of my favorite things in the new OpenEdge 11.1 release is a new plug-in for the extensible OpenEdge Identity Management framework. The two inbuilt plug-ins provided earlier allowed for user authentication against the database's _user table and against local operating system accounts. Now we have an ABL/4GL authentication plug-in mechanism that you can use to invoke your own code to do user authentication in whatever way you like.
You use the new mechanism as follows: in your application you simply create a client-principal object and set values for various fields in it. When you invoke either SET-DB-CLIENT() or SECURITY-POLICY:SET-CLIENT() then an entry-point in your previously registered 4GL callback procedure will be called. Your code then examines the presented user identity, decides whether or not it is valid, and returns either an accept or reject return code. Since we create client-principal objects under the covers when you connect to a database using the CONNECT statement and the -U user-name parameter and also when you use the SETUSERID() function, your callback will be called for those as well. This cool extension enables you to use all sorts of external authentication services as well as ones you may have built into your application.
But wait . . . that's not all! You can also use the callback mechanism with the inbuilt authentication systems to extend those. For example, you can set additional values in the client-principal object or record all user logins somewhere suitable.
To use this feature, all you have to do is set the callback procedure name in the _sec-authentication-system._PAM-callback-procedure for those authentication domains in which you want a procedure to be called.
You can find more information about this feature in Chapter 2 of the OpenEdge 11.1 manual entitled "OpenEdge Development: Programming Interfaces".
Try it. You will like it!
View all posts from Gus Bjorklund on the Progress blog. Connect with us about all things application development and deployment, data integration and digital business.
Copyright © 2016, Progress Software Corporation and/or its subsidiaries or affiliates.
All Rights Reserved.
Progress, Telerik, and certain product names used herein are trademarks or registered trademarks of Progress Software Corporation and/or one of its subsidiaries or affiliates in the U.S. and/or other countries. See Trademarks or appropriate markings.