Re: asp.net login contol using url redirect

From: Rico Wind (usenet_at_rico-wind.dk)
Date: 07/21/05


Date: Thu, 21 Jul 2005 14:21:35 +0200

Hello Dominick and thank you for you answer but i think you
misunderstood my problem.

Dominick Baier [DevelopMentor] wrote:
> Hello Rico,
>
> so the login control is in a different application on your server??
>

No the login is an integrated part of the application. The problem is
that if i open the site directly from xxx.xxx/application/login.aspx
it is functioning as expected, i.e., the user is logged in.
If however I include the site in a frame on another site, e.g.,
zzz.zzz/myframepage.html the login does not work. I expect that the
problem is that the cookie which is automaticaly created is connected to
the zzz.zzz domain and not the xxx.xxx domain, but I am not sure. And
even if I am right how do I work around this problem?
Note that the zzz.zzz domain does not use any information from the
xxx.xxx/application, the only thing is that it should be able to run
in a frame.

/rw

> the resulting authentication cookie is encrypted, with a key that is
> unique for each application. So if LoginApp1 creates and encrypts the
> cookie MainApp will not be able to decrypt the cookie again.
>
> You can manually set the key used for enc/decyption and it has to be the
> same for both apps.
>
> Have a look at the machineKey section in machine/web.config. We have a
> tool on our website which can generate you the necessary xml elements -
> just copy that to all web.configs or machine.config if you want to have
> the same key for all apps on the machine.
> http://www.develop.com/technology/resourcedetail.aspx?id=78da5ca5-5079-4f8f-99c5-b080117ceac0
>
>
> ---------------------------------------
> Dominick Baier - DevelopMentor
> http://www.leastprivilege.com
>
>> Hello
>>
>> I have an asp.net website that uses the login control and a custom
>> build
>> membership provider. The site is running fine, but the problem is that
>> i cannot use it in a frame from another site. When logging in the
>> login
>> screen just reapears. It will however give back a message if a wrong
>> username/password combination is given.
>> I could of course put the code on the site that uses the frame, but
>> the
>> component is to be used from several sites and I would really like to
>> keep the code on one server to easially be able to upgrade the
>> underlying pages.
>> /rw
>>
>
>
>



Relevant Pages

  • Re: Securing static files
    ... Dominick Baier - DevelopMentor ... they are kicked back to the login page. ... The user may log in with other credentials. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Securing static files
    ... Dominick Baier - DevelopMentor ... they are kicked back to the login page. ... The user may log in with other credentials. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: how to use
    ... Dominick Baier wrote: ... Step1:Create a Group in server computer ... create new Group and add your login id as new ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: How to disable WinNT Login Prompt
    ... does the anonymous account and the worker process account have read access to all resources? ... Dominick Baier, DevelopMentor ... will auto-login, or prompt for a login, instead I get a WinNT login ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Windows XP crashing after every boot and login
    ... My desktop Windows XP SP2 is crashing after every boot and login attempt. ... Frame IP not in any known module. ... Timestamp: unavailable ... Checksum: ...
    (microsoft.public.windowsxp.help_and_support)