{"id":197,"date":"2004-10-04T22:28:00","date_gmt":"2004-10-04T22:28:00","guid":{"rendered":"http:\/\/jclark.org\/weblog\/Programming\/Perl\/iisauth.html"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-30T04:00:00","slug":"iisauth","status":"publish","type":"post","link":"https:\/\/jclark.org\/weblog\/2004\/10\/04\/iisauth\/","title":{"rendered":"Authentication Headers and IIS"},"content":{"rendered":"<p>After spending more time than I care to admit working on a problem I actually solved in May, I decided I&#8217;d better blog this before I forget again.<\/p>\n<p>Using <a href=\"http:\/\/activestate.com\/Products\/ActivePerl\/\">ActivePerl<\/a>, it is possible to run perl CGI scripts under Microsoft IIS.  In a default installation, the extention to use is .plx (not .cgi), which is mapped to run under <code>PerlIS.dll<\/code>, the &#8220;<a href=\"http:\/\/aspn.activestate.com\/ASPN\/docs\/ActivePerl\/Components\/Windows\/PerlISAPI.html\">Perl for ISAPI<\/a>&#8221; implementation.  Works pretty well.  The issue I had was with HTTP Authentication.  If you want to handle your own authentication in a CGI script, you can check the Environment variable <code>HTTP_AUTHORIZATION<\/code>.  For example:<\/p>\n<pre><code>binmode(STDOUT, &quot;:utf8&quot;);  #you know you should\n\nmy $have_authinfo = (defined($ENV{HTTP_AUTHORIZATION}) \n    and (substr($ENV{HTTP_AUTHORIZATION},0,6) eq &#039;Basic &#039;));\n\nmy ($user, $pass) = (&#039;&#039;,&#039;&#039;);\nif ($have_authinfo) {\n    my $decoded = decode_base64(substr($ENV{HTTP_AUTHORIZATION},6));\n\n    if ($decoded =~ \/:\/) {\n        ($user, $pass) = split(\/:\/, $decoded);\n    } else {\n        $have_authinfo = 0;\n    }\n}\n\nif (!$have_authinfo or !Authorize($user, $pass)) {\n    print &lt;&lt; &quot;EOF&quot;;\nHTTP\/1.1 401 Authorization Required\nWWW-Authenticate: Basic realm=&quot;Example.com&quot;\nContent-Type: text\/plain; charset=utf-8\n\nYou must supply valid credentials to access this resource\n\nEOF\n    close STDOUT;\n    exit 0;\n}\n\n#Authorized, continue with web page....\n\nsub Authorize {\n    my ($user, $pass) = @_;\n    #Do something to authenticate, return true\/false\n}<\/code><\/pre>\n<p>Of course, I&#8217;m relying on Basic authentication, which you should only do if your script will only be available via HTTPS (as is mine).  The whole thing is dependant on <code>$ENV{HTTP_AUTHORIZATION}<\/code>, which by default won&#8217;t actually get passed to your script under IIS and PerlIS.<\/p>\n<p>Fortunately, fixing this is simple, if a bit non-evident.  In the IIS Management Console, navigate to the folder containing your script, and select the script.  Right-click and choose properties.  On the File Security tab of the properties dialog, click the Edit button under &#8220;Anonymous Access&#8221;.  On the next dialog, make sure that &#8220;Annonymous Access&#8221; is checked and that <strong>no other authentication method<\/strong> is checked.  By default, Windows Integrated Authentication is selected, which makes IIS snoop around the header, and apparently lose it.<\/p>\n<p>For multiple scripts, put them all in one location (go on, call it <code>cgi-bin<\/code>), and make the same changes above to the whole folder.  New scripts created in this folder should inherit the settings. <\/p>","protected":false},"excerpt":{"rendered":"<p>After spending more time than I care to admit working on a problem I actually solved in May, I decided I&#8217;d better blog this before I forget again. Using ActivePerl, it is possible to run perl CGI scripts under Microsoft IIS. In a default installation, the extention to use is .plx (not .cgi), which is [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[],"class_list":["post-197","post","type-post","status-publish","format-standard","hentry","category-perl"],"_links":{"self":[{"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/posts\/197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/comments?post=197"}],"version-history":[{"count":0,"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/posts\/197\/revisions"}],"wp:attachment":[{"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/media?parent=197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/categories?post=197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/tags?post=197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}