# user authenticate

**URL:** <https://forum.xojo.com/t/user-authenticate/37974>\
**Category:** Getting Started\
**Created:** [June 2, 2017, 3:06pm UTC](https://forum.xojo.com/t/user-authenticate/37974 "2017-06-02T15:06:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Francesco\_Di\_Lecce](https://forum.xojo.com/letter_avatar_proxy/v4/letter/f/858c86/32.png) [@Francesco\_Di\_Lecce](https://forum.xojo.com/u/Francesco_Di_Lecce)\
**Post date:** [June 2, 2017, 3:06pm UTC](https://forum.xojo.com/t/user-authenticate/37974/1 "2017-06-02T15:06:29Z")

</div>

I started very little to use xojo.  
I would like to use a system to authenticate users through two tables of a db mysql.  
One with the list of users and the other with the roles and their permissions  
The connection to the db is ok.  
I would like to be helped to understand how to set user login and permission control in xojo  
I tried but I find nothing about it  
thanks

---

<div class="post-metadata">

**Author:** ![Sascha\_S](https://forum.xojo.com/user_avatar/forum.xojo.com/sascha_s/32/22328_2.png) [@Sascha\_S](https://forum.xojo.com/u/Sascha_S)\
**Post date:** [June 2, 2017, 3:20pm UTC](https://forum.xojo.com/t/user-authenticate/37974/2 "2017-06-02T15:20:15Z")

</div>

If you use the mySQL Password() Function and if your Server uses the old Password Format, you can compare the Hash of the entered Password with the Hash from the mySQL Server/Database

```auto
thePasswordHash As String = EncodeHex(MD5(thePassword))
```

---

<div class="post-metadata">

**Author:** ![Louis\_D](https://forum.xojo.com/letter_avatar_proxy/v4/letter/l/cab0a1/32.png) [@Louis\_D](https://forum.xojo.com/u/Louis_D)\
**Post date:** [June 2, 2017, 3:47pm UTC](https://forum.xojo.com/t/user-authenticate/37974/3 "2017-06-02T15:47:50Z")

</div>

I use an approach similar to what you want to do.  
Step 1 is the same approach as suggested by Sascha. I now have a user.  
Step 2 is to query the second table and get permissions for my application. I use a multi-level approach with transaction codes, transaction objects and function codes. Permissions are set on either or all levels.

Depending on the application, you can query all of the user permissions at once, or query specifically when trying to access a transaction. Transaction-based and object-based permissions can be a lot of work both to setup the methods and to maintain the necessary master data.

---

<div class="post-metadata">

**Author:** ![Francesco\_Di\_Lecce](https://forum.xojo.com/letter_avatar_proxy/v4/letter/f/858c86/32.png) [@Francesco\_Di\_Lecce](https://forum.xojo.com/u/Francesco_Di_Lecce)\
**Post date:** [June 2, 2017, 6:18pm UTC](https://forum.xojo.com/t/user-authenticate/37974/4 "2017-06-02T18:18:35Z")

</div>

thanks for reply  
i have mySQL 5.5  
i make this:  
in mySQL DB i store: OLD\_PASSWORD(‘admin’) and i see: 43e9a4ab75570f5b  
in mySQL DB i store: PASSWORD(‘admin’) and i see: \*4ACFE3202A5FF5CF467898FC58AAB1D615029441

but in xojo  
EncodeHex (MD5 (TextFieldPasswd.Text))=21232F297A57A5A743894A0E4A801FC3

I do not understand

can you help me?

---

<div class="post-metadata">

**Author:** ![Francesco\_Di\_Lecce](https://forum.xojo.com/letter_avatar_proxy/v4/letter/f/858c86/32.png) [@Francesco\_Di\_Lecce](https://forum.xojo.com/u/Francesco_Di_Lecce)\
**Post date:** [June 2, 2017, 9:27pm UTC](https://forum.xojo.com/t/user-authenticate/37974/5 "2017-06-02T21:27:32Z")

</div>

ok i solved.  
the error is that in mysql not specify anyting, i store only: MD5(‘admin’)

thanks at all!!

---

<div class="post-metadata">

**Author:** ![system](https://forum.xojo.com/uploads/default/original/1X/455b4dcc0e61630e9f81940004ddffa49c432a46.png) [@system](https://forum.xojo.com/u/system)\
**Post date:** [October 29, 2020, 6:47pm UTC](https://forum.xojo.com/t/user-authenticate/37974/6 "2020-10-29T18:47:47Z")

</div>


