# Form Authentication with aFleX

**URL:** <https://community.a10networks.com/t/form-authentication-with-aflex/186>\
**Category:** aFleX\
**Created:** [January 15, 2013, 6:02pm UTC](https://community.a10networks.com/t/form-authentication-with-aflex/186 "2013-01-15T18:02:13Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![mischa](https://avatars.discourse-cdn.com/v4/letter/m/b9bd4f/32.png) [@mischa](https://community.a10networks.com/u/mischa)\
**Post date:** [January 15, 2013, 6:02pm UTC](https://community.a10networks.com/t/form-authentication-with-aflex/186/1 "2013-01-15T18:02:13Z")

</div>

Quick and dirty way of form based authenticating users for specific URLs on a VIP.

`### START ### when RULE\_INIT { # List of users (with passwords) that are allowed to authenticate array set ::DOTPASSWD { “randomuser1” “thiswillbeacleartextpassword” “randomuser2” “thiswillbeacleartextpassword” }

set ::FORM\_CONTENT "AuthenticationPlease AuthenticateUsername:Password: " }

when HTTP\_REQUEST { set client\_ip [IP::client\_addr] set persist\_entry [persist lookup uie $client\_ip] if { [HTTP::method] eq “POST” and $persist\_entry eq “” } { HTTP::collect } elseif { [HTTP::method] ne “POST” and $persist\_entry eq “” } { HTTP::respond 200 content $::FORM\_CONTENT } } when HTTP\_REQUEST\_DATA { set client\_ip [IP::client\_addr] if { [HTTP::method] eq “POST”} { log “PAYLOAD: [HTTP::payload]” set auth\_string [HTTP::payload] regexp -nocase {form\_username=(._)&form\_password=(._)} $auth\_string matchall auth\_user auth\_passwd if { [info exists ::DOTPASSWD($auth\_user)] } { set stored\_passwd $::DOTPASSWD($auth\_user) if { $auth\_passwd eq $stored\_passwd } { set ::AUTHENTICATED “yes” } else { HTTP::respond 200 content $::FORM\_CONTENT } } else { HTTP::respond 200 content $::FORM\_CONTENT } } else { HTTP::respond 200 content $::FORM\_CONTENT } } when HTTP\_RESPONSE { if { $::AUTHENTICATED eq “yes” } { persist add uie { $client\_ip } 600 } } ### END ###`
