Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Programming > ASP .Net > Cookieless Authentication and Relative HTML References

Reply
Thread Tools

Cookieless Authentication and Relative HTML References

 
 
Mark Olbert
Guest
Posts: n/a
 
      01-15-2006
I have a website (ASPNET2) which uses cookieless authentication.

<img> tags on restricted-access aspx pages appear to need the URL credential fragment (i.e., the long string that encodes the user's
credentials) to be found...which is contrary to my understanding (under 1.1, at least) as to how resources are controlled. Example:

This tag on a restricted-access aspx page:

<img src="/data/somefile.gif">

Shows up as "not found" (i.e., the image contains a red x). So I tried to surf to:

http://localhost:<port>/site/data/somefile.gif

and got a resource not found error.

But this URL:

http://localhost<port>/<long user credential fragment>/data/somefile.gif"

displays the expected image.

Did something change between 1.1 and 2.0 in this arena?

- Mark
 
Reply With Quote
 
 
 
 
Steven Cheng[MSFT]
Guest
Posts: n/a
 
      01-16-2006
Hi Mark,

Welcome.
As for the image file displaying in Cookieless forms authentication
protected website (asp.net 2.0), are you developing and testing the
application in buildin test server rather than IIS? If so, this is the
expected behavior because IIS server can handle both static file resources
directly or forward the request to ASP.NET runtime, however when using
buildin test server, all the requests are handled by the test
server(asp.net isapi...) ,then when we using
FormsAuthenticaiotn(cookieless), the related httpmodule will always handle
the request and try authenticate the user (through the embeded user token
string....) so when using a url string without the authenticated uesr's
credential(embeded string), it will occur some problems. In IIS, the
static non-embeded token image url will be used to request the static
resources, you can check the IIS log to see whether web requests....

Regards,

Steven Cheng
Microsoft Online Support

Get Secure! www.microsoft.com/security
(This posting is provided "AS IS", with no warranties, and confers no
rights.)



--------------------
| NNTP-Posting-Date: Sat, 14 Jan 2006 21:07:57 -0600
| From: Mark Olbert <>
| Newsgroups: microsoft.public.dotnet.framework.aspnet
| Subject: Cookieless Authentication and Relative HTML References
| Date: Sat, 14 Jan 2006 19:07:56 -0800
| Organization: Olbert & McHugh, LLC
| Reply-To:
| Message-ID: <>
| X-Newsreader: Forte Agent 3.1/32.783
| MIME-Version: 1.0
| Content-Type: text/plain; charset=us-ascii
| Content-Transfer-Encoding: 7bit
| Lines: 24
| X-Trace:
sv3-8NDckWorfOtUsObhbKeueGZpPZkCsgytWyBEu72Ja2xP3s0IS0 HzH0K5o7PAQiFurPZkUG+9
0sR1J2k!YlouEOpLb0hSDH+DCkoga94MJLchy1Uy8zgyE62ofl 1jiI6d+cYITXHAHv1TKwpV3p03
gQ==
| X-Complaints-To:
| X-DMCA-Notifications: http://www.giganews.com/info/dmca.html
| X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
| X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your
complaint properly
| X-Postfilter: 1.3.32
| Path:
TK2MSFTNGXA02.phx.gbl!TK2MSFTNGP08.phx.gbl!newsfee d00.sul.t-online.de!t-onli
ne.de!border2.nntp.dca.giganews.com!border1.nntp.d ca.giganews.com!nntp.gigan
ews.com!local01.nntp.dca.giganews.com!news.giganew s.com.POSTED!not-for-mail
| Xref: TK2MSFTNGXA02.phx.gbl
microsoft.public.dotnet.framework.aspnet:370903
| X-Tomcat-NG: microsoft.public.dotnet.framework.aspnet
|
| I have a website (ASPNET2) which uses cookieless authentication.
|
| <img> tags on restricted-access aspx pages appear to need the URL
credential fragment (i.e., the long string that encodes the user's
| credentials) to be found...which is contrary to my understanding (under
1.1, at least) as to how resources are controlled. Example:
|
| This tag on a restricted-access aspx page:
|
| <img src="/data/somefile.gif">
|
| Shows up as "not found" (i.e., the image contains a red x). So I tried to
surf to:
|
| http://localhost:<port>/site/data/somefile.gif
|
| and got a resource not found error.
|
| But this URL:
|
| http://localhost<port>/<long user credential fragment>/data/somefile.gif"
|
| displays the expected image.
|
| Did something change between 1.1 and 2.0 in this arena?
|
| - Mark
|

 
Reply With Quote
 
 
 
 
Mark Olbert
Guest
Posts: n/a
 
      01-16-2006
Ouch! That's an annoying limitation of the "builtin" http server. Thanx for the info.

- Mark
 
Reply With Quote
 
Steven Cheng[MSFT]
Guest
Posts: n/a
 
      01-17-2006
You're welcome Mark,

I think the dev guys really omit such a scenario that use cookieless
authentication in testserver and directly requesting image through normal
url... I suggest you also submit it to the MSDN feedback center for their
reference:

http://lab.msdn.microsoft.com/produc...k/default.aspx

Thanks & Regards,

Steven Cheng
Microsoft Online Support

Get Secure! www.microsoft.com/security
(This posting is provided "AS IS", with no warranties, and confers no
rights.)
--------------------
| NNTP-Posting-Date: Mon, 16 Jan 2006 10:15:17 -0600
| From: Mark Olbert <>
| Newsgroups: microsoft.public.dotnet.framework.aspnet
| Subject: Re: Cookieless Authentication and Relative HTML References
| Date: Mon, 16 Jan 2006 08:15:18 -0800
| Organization: Olbert & McHugh, LLC
| Reply-To:
| Message-ID: <>
| References: <>
<>
| X-Newsreader: Forte Agent 3.1/32.783
| MIME-Version: 1.0
| Content-Type: text/plain; charset=us-ascii
| Content-Transfer-Encoding: 7bit
| Lines: 3
| X-Trace:
sv3-M2778cOofvv+7pUouc91nYf8amNi1MIP1TrvhT7vCSEChTreHr 8ihFA6wrhX9uMtZIzF80Dh
UvABJDm!rXz2Kd8S61nBVIeGz2LeRDM4s8pTceLWMXkb8LUz0w Ivk8HzLW1x1oeaFRL5bemj1PDc
IA==
| X-Complaints-To:
| X-DMCA-Notifications: http://www.giganews.com/info/dmca.html
| X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
| X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your
complaint properly
| X-Postfilter: 1.3.32
| Path:
TK2MSFTNGXA02.phx.gbl!TK2MSFTNGP08.phx.gbl!newsfee d00.sul.t-online.de!t-onli
ne.de!border2.nntp.dca.giganews.com!border1.nntp.d ca.giganews.com!nntp.gigan
ews.com!local01.nntp.dca.giganews.com!news.giganew s.com.POSTED!not-for-mail
| Xref: TK2MSFTNGXA02.phx.gbl
microsoft.public.dotnet.framework.aspnet:371159
| X-Tomcat-NG: microsoft.public.dotnet.framework.aspnet
|
| Ouch! That's an annoying limitation of the "builtin" http server. Thanx
for the info.
|
| - Mark
|

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to set userdata in auth ticket and still support cookieless authentication? Peter Rilling ASP .Net 1 08-03-2006 03:45 PM
sessionState cookieless and forms cookieless ravisingh11@gmail.com ASP .Net 2 05-09-2006 11:26 PM
Cookieless Forms Authentication and Roles Mark Olbert ASP .Net 1 12-26-2005 09:51 AM
Difference between bin and obj directories and difference between project references and dll references jakk ASP .Net 4 03-22-2005 09:23 PM
Authentication ticket, cookieless, forms authentication? Lauchlan M ASP .Net Security 0 10-01-2003 12:23 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57