Wednesday, May 20, 2009

HelpNDoc let's you generate help files in various formats from a single source

  • CHM: Compiled Microsoft Windows HTML Help;

  • HTML: Complete web help optimized for easy online browsing and search engines;

  • DOC: Complete help documentation as a Microsoft Word document or RTF file;

  • PDF: Standard Adobe portable document format documentation for easy sharing and printing;

  • HelpNDoc includes a complete WYSIWYG editor with advanced formatting and layout capabilities.



    • Advanced paragraph formatting: alignment, indentation, line spacing, tabs and text flow;

    • Advanced font customization: character spacing, offset, scaling, superscripts and subscripts;

    • Extensive image format support: JPG, PNG, GIF, BMP, ICO, EMF, WMF;

    • Advanced table support: cell padding and spacing, alignment, customizable borders and fills;

    • Complete live spell checker with custom dictionaries and automatic corrections;

  • Table of content editor with instant reorganization and customization;

  • Extremely fast topic creation, deletion and customization;

  • Advanced keywords editor: easily attach keywords with topics, categorize and manage them;

  • Automatic Topic ID and Context number generation;

  • Writing and integrating help files has never been easier thanks to HelpNDoc's advanced functionalities.



    • Live external document import: the document will be imported when the help file is generated;

    • Project or user defined variables: the variable will be replaced when the help file is generated;

    • Project-wide efficient find and replace tool: find a sentence and replace it by a variable;

    • Multiple language code generation: C/C++ headers, Delphi units, Visual Basic and Fortran modules to ease help file interaction;

    • Extensive command line support to pilot HelpNDoc from an external application, an automated processing or a batch script;

    Delphi Prism Web Services and SOAP Security

    In this article, I'll demonstrate how to use SOAP Headers as security technique for ASP.NET Web Service projects using Delphi Prism (extending the example from last month by adding a security layer to it).


    SOAP Headers

    In order to work with SOAP Headers in an ASP.NET Web Service, we have to add System.Web.Services.Protocols to the uses clause, and define a new class derived from the SoapHeader class found in the aforementioned namespace.
    The new class can be called anything, so I've decided to call it TCredentials (I know that in the .NET Framework you're not supposed to prefix everything with a "T", but since I'm a proud Delphi developer, I always use a T prefix for my types).


    It must be a public class, since we need to export it so any client importing our ASP.NET web service can also know about it.
    Adding a Username and Password field to the TCredentials class, this could lead to the following definition.



    type
    TCredentials = public class(System.Web.Services.Protocols.SoapHeader)
    public
    Username: String;
    Password: String;
    end;


    With this class definition in mind, we can add a public field (for example called token) to the public class Service, as well as a private method (for example called CheckCredentials) to check if the credentials have been received and contain the correct username/password information.
    This leads to the following modification of the Service class:



    Service = public class(System.Web.Services.WebService)
    public
    var

    token: TCredentials;

    private
    method
    CheckCredentials: Boolean;


    In order to specify that the token has to be used for certain web method (from the original set), we have to add the attribute SoapHeader to the web method, specifying the token as well as the direction in which the token is assigned (in our case only on input, so only the web service client will be writing information in the token, and the Service web service "engine" can check the token for valid credentials by looking at its value).


    Using the example from last month, we can modify some of the web methods as follows:



    public
    [WebMethod(EnableSession := true)]
    [SoapHeader('token', Direction := SoapHeaderDirection.&In)]
    method Remember(const Name,Value: String);

    [WebMethod(EnableSession := true)]
    [SoapHeader('token', Direction := SoapHeaderDirection.&In)]
    method Recall(const Name: String): String;

    [WebMethod(EnableSession := true)]
    method Forget(const Name: String);

    [WebMethod(EnableSession := true)]
    method Amnesia; // forget all
    end;


    Note that I only added the SoapHeader attribute to the Remember and Recall web methods, and not to the Forget or Amnesia methods.
    In other words: you are free to forget, but in order to remember or recall something, you need security clearance.


    Inside that Remember and Recall methods, we will have to call the CheckCredentials method before doing their actual work, in order to verify the value of the token.
    Which leads us to the implementation of CheckCredentials, which is shown below (using a hard-coded check for the values of the Username and Password properties of the token - you should obviously implement a stronger check here!).


    Note that apart from returning False is the Username and Password are incorrect, we can also raise an exception, for example if the token is not found in the SOAP header (which might happen if the web service is consumed and used by web service client applications who do not add the token to the SOAP header in the first place).



    method Service.CheckCredentials: Boolean;
    begin
    Result := False;
    if not Assigned(token) then
    raise
    ApplicationException.Create('No token in SOAP Header!');

    if (token.Username.ToLower = 'bob') and
    (token.Password.ToLower = 'swart') then Result := True
    end;


    The implementation of Remember and Recall can simple be extended by calling the CheckCredentials method before doing anything:



    method Service.Remember(const Name,Value: String);
    begin
    if
    CheckCredentials then
    Session[Name] := Value
    end;

    method Service.Recall(const Name: String): String;
    begin
    if
    CheckCredentials then
    if
    Assigned(Session[Name]) then
    Result := Session[Name].ToString
    else Result := ''
    end;


    Note that Forget and Amnesia remain unchanged, since you are always allowed to forget:



    method Service.Forget(const Name: String);
    begin
    Session.Remove(Name) // always allowed
    end;

    method Service.Amnesia;
    begin
    Session.Abandon // always allowed
    end;


    Before deploying and consuming this new secure web service, there's one thing to keep in mind about using SOAP Headers: the contents are sent in plain text over the network.
    So passing a username and password inside a SOAP Header is adding authorization capabilities, but still lacks a little security.
    For that reason, I always recommend to use SOAP Headers in combination with HTTPS and SSL.
    That way, the traffic between the web service and client is encrypted, and nobody else should be able to decypher the information sent by the client to the server (since it's encrypted with the public key from the server, and can only be decrypted by the private key of the server, so anyone sniffing the network only gets an encrypted package).


    Implementing HTTPS and SSL requires two things: first, you should purchase a certificate and install it on your web server (or ask your provider if a certificate is already available for use by your web service), and second, all URLs that are used to communicate with the web service should use https:// and not http://.


    For this example, I give you the option of exploring the difference, so I've deployed the secure web service on two different web servers: one with HTTPS and one without.
    On one server, you can access the web service via http://www.bobswart.net/MyWebService/Service.asmx and on the other (secure) web server you have to use HTTPS and the URL https://www.bobswart.nl/MyWebService/Service.asmx instead.


    Both will work the same (the MyWebService.dll code behind assembly is exactly the same on both machines), but one connection is more secure than the other, which is important when using SOAP Headers.

    Wednesday, May 13, 2009

    Move TPageControl's Tabs Using Drag and Drop in Delphi Applications

    TPageControl is a set of pages used to make a multiple page dialog box. Why not enable your users to rearrange tabs in a TPageControl component at run-time using drag and drop...
    Drop a TPageControl on a form, add several (tab) pages and handle the MouseDown, DragDrop and DragOver events of the TPageControl (PageControl1) component


    Why not enable your users to rearrange tabs in a TPageControl component at run time using drag and drop...
    Drop a TPageControl on a form, add several (tab) pages and handle the MouseDown, DragDrop and DragOver events of the TPageControl (PageControl1) component.


    procedure TMainForm.PageControl1MouseDown(Sender: TObject;
    Button: TMouseButton; Shift: TShiftState; X, Y: Integer) ;
    begin
    PageControl1.BeginDrag(False) ;
    end;

    procedure TMainForm.PageControl1DragDrop(Sender, Source: TObject; X,
    Y: Integer) ;
    const
    TCM_GETITEMRECT = $130A;
    var
    TabRect: TRect;
    j: Integer;
    begin
    if (Sender is TPageControl) then
    for j := 0 to PageControl1.PageCount - 1 do
    begin
    PageControl1.Perform(TCM_GETITEMRECT, j, LParam(@TabRect)) ;
    if PtInRect(TabRect, Point(X, Y)) then
    begin
    if PageControl1.ActivePage.PageIndex <> j then
    PageControl1.ActivePage.PageIndex := j;
    Exit;
    end;
    end;
    end;

    procedure TMainForm.PageControl1DragOver(Sender, Source: TObject; X,
    Y: Integer; State: TDragState; var Accept: Boolean) ;
    begin
    if (Sender is TPageControl) then Accept := True;
    end;

    Tuesday, May 12, 2009

    What is an Access Violation

    Every computer program uses memory for running (*). Memory is consumed by every variable in your program. It can be form, component, object, array, record, string or simple Integer. Memory can be allocated automatically for certain types of variables (such as Integer or static arrays), the other types require manual control of memory (for example, dynamic arrays). Essentially, from the point of operating system, each variable is characterized by its address (i.e. - location) and size.

    Roughly speaking, program uses 3 “types” of memory: area for global variables, the stack and the heap.
    Memory for global variables is allocated by OS loader when executable module is loading and it is freed when module is unloading. Global variables are those, which declared outside of class or any routine. The stack is used for allocating memory for local variables (which are declared in some function or procedure) and auxiliary data (such as return addresses or exception handlers). The heap is used for storing dynamic data.
    Note, that for variables of dynamic types (such as dynamic arrays, strings, objects or components) - though the variable itself is stored in global area or stack, but its data is always allocated on the heap and it (often) require manual control.

    Regardless of who allocates memory for the variable (you, manually or the compiler, automatically), memory for each variable must be allocated before its using, and later (when the variable is no longer needed) it should be freed.
    Sometimes there can be a situation, where your application trying to get access to certain memory location, which wasn’t allocated or was already released - due to bugs in your code. When such things happens - the CPU raises an exception of class EAccessViolation. The usual text for this error is as follows: “Access violation at address XXX in module ‘YYY’. Write/read of address ZZZ”. Though there is the one simple reason for this kind of error, the real situations for it can be very different.

    Sunday, May 10, 2009

    The server records for small business

    Usually the boss needs accurate reports on all divisions «here and now» – in such moments, there is neither time, nor means to acquire and implement big cooperative systems. But, there is an easy solution to such tasks.

    Maybe, you had to undertake the installation of automatic systems at film level. Any such system must accumulate data, process it and give the result. Usually, there is already a working program support, which does all this, but when the data is accumulated, sometimes it happens that, the process is not enough and there isn’t the needed report. It is okay, if it’s possible to turn to the developer and ask to do everything, but this is not possible, if the program was installed a long time ago or was bought in a box .In this case, it is important to get a limited fast result which can satisfy the boss and will not be very expensive. The tools for IT development-infrastructure are now, as a rule, limited. But because of the automation, there is need to optimize the business process now, controlling it and as a result, future economy.

    Often there is need to do a difficult job, collect data from several bases, connect them together,analyse it and give the result in a group, accessible for analysis and controlling. The data can be different – text file, data base in the formats DBF-file, electronic file table. It happens that, the similar task cannot be solved or needs a lot of money to develop a specific program. Here, one might refuse automation, or to creating a specific solution – using early operating time and collecting constructors from different program «blocks», collect everything from the module available at the market, do a minimum binding and build upon a certain task.

    The company Fast Reports (fast-report.com) has got several program products on the market, which can substantially lessen the solution to the above given tasks. This is the very missing «block», which can handle the creation of reports and the given data in the needed form. The base to all these solutions, is a powerful report generator FastReport, which has shown itself to be dependable, fast and an easy solution for data processing. 11 years of successful work at the market has allowed the company to create an easy to use program product for information systems developers and users to create needed reports

    One of FastReports flag products – Report server. It is a stand-alone HTTP-server, which can be installed on any computer on a local network under the MS Windows 2000 and above operating system. Apart from the function saving static files, it can process query concerning the creation of reports, including the prior entrance of data through web forms. The user receives the result in form of HTML-page, by using an ordinary web browser or the format needed by him, for example, PDF, Open Office, Rich Text и and many others. The printing function is accessible on any printer on the network, registered on the computer, where FastReport Server, works. Server settings are very easy. Generally, it is ready to be used immediately after installation. If on the computer, there is already a different web server installed, then, only changing the number of the working port and restarting FastReportServer, is needed. It is possible to work together with the already installed web servers like IIS and Apache with the help of the CGI- application or in form of ISAP-module which comes with the FastReport Server packet. Doing that makes the running of the individual servers unnecessary – all the functions of the report server will concentrate on ISAPI DLL. All the server settings will be saved in xml-file, supplying comments and can be changed with the help of the program-configuration. All reports, being done on the FastReport Server, are compatible with the FastReport 4 format and can be transferred from early developed programs, in which FastReport 4 was. The user can, develop his own reports with the help of the FastReport Studio, report designer. Trial version comes together with the server packet, and the license of FastReport Studio Single the buyer of server, receives as a present. It is important to note the possibility of FastReport to create several connections to the data base in one report and collect information from different data bases. Generally, any data can be used, accessible through ODBC-driver

    Not long ago, Fast Reports released an update of its server solution. FastReport Server 2.1 has become stable and faster, improved the interaction with famous web servers like Microsoft IIS and Apache. The most important innovation became the possibility to use in the MS Windows authentication , which opens the possibility for a tight integration in the Active Directory domain and make simpler the running of records account and users group – each users group can form a report which it needs – managing – someone, accountant – another. And every user can be absolutely calm because of the accuracy of the information being received – the report will be formed on its query exactly at that moment, when it is needed!