Skip to content

Security Login — Reference

Reference · Advanced · Server Connect

Validate credentials and establish the selected provider’s authenticated session.

Validate credentials and establish the selected provider’s authenticated session.

  • A configured Security Provider and a disposable test account for verifying authentication behavior.

Validate credentials and establish the selected provider’s authenticated session.

Setting Meaning and example
UsernameThe user name expression. By default this is $_POST.username; bind it explicitly when your incoming field has another name.
PasswordThe submitted password expression, defaulting to $_POST.password. With hash verification enabled on a database provider, pass the original password; the provider checks it against the stored hash.
RememberWhether to create the provider’s persistent login cookie. It defaults to the incoming remember value. Send a deliberate boolean or expected form value rather than a non-empty string that merely says false.
OutputIncludes the login result identity in the action response. The rule initializes it on.
ProviderThe Security Provider configuration to validate against. It must exist and match the user source and password-storage scheme.
Result nameThe action rule uses identity as its hidden/default result name; it is not a separate visible Name control in this inspector.

Use a test account with the provider’s supported password format. Submit username/password to an action containing Security Login. Check a successful login, a wrong password, and then Security Identify in a subsequent request from the same browser session.

A normal invalid login returns unauthorized behavior from the provider, commonly HTTP 401; it is not a successful result containing a generic error string. This step does not automatically navigate the top-level page after an AJAX submission. Use the page’s success/error handling for that behavior.

Use the security and login guides for the surrounding provider, form, session and server-access configuration.

You can configure the documented fields and distinguish a successful result from the failure or limitation described here.