Forms authentication doesn't work for downloads

From: Peter Afonin (pva_at_speakeasy.net)
Date: 11/23/04


Date: Tue, 23 Nov 2004 12:41:20 -0800

Hello,

I'm using Forms authentication, and it works well. If user is not
authenticated, he is routed to the login page.

However, this doesn't work for downloads. If I have a file located in the
restricted area and put a direct link to it - anyone can download it.

Why is this? I expected that people would also be routed to the login
screen. How to make this happen?

I would appreciate your help.

Thank you,

-- 
Peter Afonin


Relevant Pages

  • Re: Forms authentication doesnt work for downloads
    ... That is aspx,asmx, config and such. ... DOC and other file types with Forms Authentication ... this doesn't work for downloads. ... I expected that people would also be routed to the login ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Forms authentication doesnt work for downloads
    ... Forms authentication is handled by the framework - thus you likely need to ... pass that type of file through the asp.net handler by mapping it in IIS... ... this doesn't work for downloads. ... I expected that people would also be routed to the login ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • [Full-Disclosure] Advisory: Dark Age of Camelot - Weak encryption of network traffic exposed persona
    ... Weak encryption in game client exposed customer billing and authentication ... encryption for billing information. ... The login binary has undergone several updates since then. ...
    (Full-Disclosure)
  • Re: [PHP] Is this the best way?
    ... Why is Jason schreefing again? ... maybe I should edit my authentication function... ... attempting to login. ... really be either attempting an authentication *or* outputting some ...
    (php.general)
  • Authentication Sharing Across Apps
    ... For my part "B" question that I had (Login App was not returning ... authentication to calling app), I found the solution. ... Basically, in both the Login App and Calling App Web.Config, I did ... authenticated connection with SQL server. ...
    (microsoft.public.dotnet.framework.aspnet.security)