Security Login — Reference
Validate credentials and establish the selected provider’s authenticated session.
Validate credentials and establish the selected provider’s authenticated session.
Before you begin
Section titled “Before you begin”- A configured Security Provider and a disposable test account for verifying authentication behavior.
Security Login
Section titled “Security Login”Validate credentials and establish the selected provider’s authenticated session.
Settings
Section titled “Settings”| Setting | Meaning and example |
|---|---|
| Username | The user name expression. By default this is $_POST.username; bind it explicitly when your incoming field has another name. |
| Password | The submitted password expression, defaulting to $_POST.password. With hash verification enabled on a database provider, pass the original password; the provider checks it against the stored hash. |
| Remember | Whether to create the provider’s persistent login cookie. It defaults to the incoming remember value. Send a deliberate boolean or expected form value rather than a non-empty string that merely says false. |
| Output | Includes the login result identity in the action response. The rule initializes it on. |
| Provider | The Security Provider configuration to validate against. It must exist and match the user source and password-storage scheme. |
| Result name | The action rule uses identity as its hidden/default result name; it is not a separate visible Name control in this inspector. |
Verification example
Section titled “Verification example”Use a test account with the provider’s supported password format. Submit username/password to an action containing Security Login. Check a successful login, a wrong password, and then Security Identify in a subsequent request from the same browser session.
Behavior and limits
Section titled “Behavior and limits”A normal invalid login returns unauthorized behavior from the provider, commonly HTTP 401; it is not a successful result containing a generic error string. This step does not automatically navigate the top-level page after an AJAX submission. Use the page’s success/error handling for that behavior.
Use the complete authentication flow
Section titled “Use the complete authentication flow”Use the security and login guides for the surrounding provider, form, session and server-access configuration.
Check your result
Section titled “Check your result”You can configure the documented fields and distinguish a successful result from the failure or limitation described here.