Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Programming > ASP .Net > ASP .Net Security > Securing content via .NET ISAPI filter

Reply
Thread Tools

Securing content via .NET ISAPI filter

 
 
Bill Belliveau
Guest
Posts: n/a
 
      04-27-2005
I’m trying to protect some content on a web application from un-authenticated
users based on forms authentication.

So far I’ve added the extension (.swf) to the application configuration in
IIS. If I select the checkbox ‘Script engine’, all works fine except for the
fact that you can directly access the object by a specific url without
authentication, assuming you know the path. With the ‘Script engine’
disabled no one, including authenticated users, cannot access the resources.

I’ve reset the file permission on the site to default to no avail. The site
is running on Windows 2003 server using only anonymous access and an
application pool running with the identity of local system.

I am not authenticating the forms logon using the typical methodology of
“FormsAuthentication.RedirectFromLoginPage”, rather users are given an
encrypted URL that contains what access they are allowed. I am using
FormsAuthentication.SetAuthCookie(strEmail, false); to acknowledge the access.

The authentication appears to be work properly as I can test (e.g. bool test
= Context.User.Identity.IsAuthenticated with returns the correct results.

There appears to be a crucial issue I’m apparently missing.. Any Ideas?

Thanks,
Bill Belliveau
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ISAPI filter or http module Guoqi Zheng ASP .Net 10 01-27-2005 04:00 PM
Using ISAPI filter with .net for URL Rewriting Jon Maz ASP .Net 2 09-30-2004 02:04 PM
How do use change the default http handler in ASP,NET similar to ISAPI filter ? Anonieko Ramos ASP .Net 0 05-12-2004 11:18 AM
Framework 1.1 upgrade and ISAPI Filter Change Not Working Jeremy ASP .Net 1 08-29-2003 04:33 PM
ASP.NET and custom ISAPI filter authentication Michael Shutt ASP .Net 0 06-26-2003 02:31 PM



Advertisments