473,383 Members | 1,963 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,383 software developers and data experts.

Cookieless Authentication and Relative HTML References

I have a website (ASPNET2) which uses cookieless authentication.

<img> tags on restricted-access aspx pages appear to need the URL credential fragment (i.e., the long string that encodes the user's
credentials) to be found...which is contrary to my understanding (under 1.1, at least) as to how resources are controlled. Example:

This tag on a restricted-access aspx page:

<img src="/data/somefile.gif">

Shows up as "not found" (i.e., the image contains a red x). So I tried to surf to:

http://localhost:<port>/site/data/somefile.gif

and got a resource not found error.

But this URL:

http://localhost<port>/<long user credential fragment>/data/somefile.gif"

displays the expected image.

Did something change between 1.1 and 2.0 in this arena?

- Mark
Jan 15 '06 #1
3 1306
Hi Mark,

Welcome.
As for the image file displaying in Cookieless forms authentication
protected website (asp.net 2.0), are you developing and testing the
application in buildin test server rather than IIS? If so, this is the
expected behavior because IIS server can handle both static file resources
directly or forward the request to ASP.NET runtime, however when using
buildin test server, all the requests are handled by the test
server(asp.net isapi...) ,then when we using
FormsAuthenticaiotn(cookieless), the related httpmodule will always handle
the request and try authenticate the user (through the embeded user token
string....) so when using a url string without the authenticated uesr's
credential(embeded string), it will occur some problems. In IIS, the
static non-embeded token image url will be used to request the static
resources, you can check the IIS log to see whether web requests....

Regards,

Steven Cheng
Microsoft Online Support

Get Secure! www.microsoft.com/security
(This posting is provided "AS IS", with no warranties, and confers no
rights.)

--------------------
| NNTP-Posting-Date: Sat, 14 Jan 2006 21:07:57 -0600
| From: Mark Olbert <Ch*********@newsgroups.nospam>
| Newsgroups: microsoft.public.dotnet.framework.aspnet
| Subject: Cookieless Authentication and Relative HTML References
| Date: Sat, 14 Jan 2006 19:07:56 -0800
| Organization: Olbert & McHugh, LLC
| Reply-To: ma**@arcabama.com
| Message-ID: <iq********************************@4ax.com>
| X-Newsreader: Forte Agent 3.1/32.783
| MIME-Version: 1.0
| Content-Type: text/plain; charset=us-ascii
| Content-Transfer-Encoding: 7bit
| Lines: 24
| X-Trace:
sv3-8NDckWorfOtUsObhbKeueGZpPZkCsgytWyBEu72Ja2xP3s0IS0 HzH0K5o7PAQiFurPZkUG+9
0sR1J2k!YlouEOpLb0hSDH+DCkoga94MJLchy1Uy8zgyE62ofl 1jiI6d+cYITXHAHv1TKwpV3p03
gQ==
| X-Complaints-To: ab***@giganews.com
| X-DMCA-Notifications: http://www.giganews.com/info/dmca.html
| X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
| X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your
complaint properly
| X-Postfilter: 1.3.32
| Path:
TK2MSFTNGXA02.phx.gbl!TK2MSFTNGP08.phx.gbl!newsfee d00.sul.t-online.de!t-onli
ne.de!border2.nntp.dca.giganews.com!border1.nntp.d ca.giganews.com!nntp.gigan
ews.com!local01.nntp.dca.giganews.com!news.giganew s.com.POSTED!not-for-mail
| Xref: TK2MSFTNGXA02.phx.gbl
microsoft.public.dotnet.framework.aspnet:370903
| X-Tomcat-NG: microsoft.public.dotnet.framework.aspnet
|
| I have a website (ASPNET2) which uses cookieless authentication.
|
| <img> tags on restricted-access aspx pages appear to need the URL
credential fragment (i.e., the long string that encodes the user's
| credentials) to be found...which is contrary to my understanding (under
1.1, at least) as to how resources are controlled. Example:
|
| This tag on a restricted-access aspx page:
|
| <img src="/data/somefile.gif">
|
| Shows up as "not found" (i.e., the image contains a red x). So I tried to
surf to:
|
| http://localhost:<port>/site/data/somefile.gif
|
| and got a resource not found error.
|
| But this URL:
|
| http://localhost<port>/<long user credential fragment>/data/somefile.gif"
|
| displays the expected image.
|
| Did something change between 1.1 and 2.0 in this arena?
|
| - Mark
|

Jan 16 '06 #2
Ouch! That's an annoying limitation of the "builtin" http server. Thanx for the info.

- Mark
Jan 16 '06 #3
You're welcome Mark,

I think the dev guys really omit such a scenario that use cookieless
authentication in testserver and directly requesting image through normal
url... I suggest you also submit it to the MSDN feedback center for their
reference:

http://lab.msdn.microsoft.com/produc...k/default.aspx

Thanks & Regards,

Steven Cheng
Microsoft Online Support

Get Secure! www.microsoft.com/security
(This posting is provided "AS IS", with no warranties, and confers no
rights.)
--------------------
| NNTP-Posting-Date: Mon, 16 Jan 2006 10:15:17 -0600
| From: Mark Olbert <Ch*********@newsgroups.nospam>
| Newsgroups: microsoft.public.dotnet.framework.aspnet
| Subject: Re: Cookieless Authentication and Relative HTML References
| Date: Mon, 16 Jan 2006 08:15:18 -0800
| Organization: Olbert & McHugh, LLC
| Reply-To: ma**@arcabama.com
| Message-ID: <jj********************************@4ax.com>
| References: <iq********************************@4ax.com>
<2n**************@TK2MSFTNGXA02.phx.gbl>
| X-Newsreader: Forte Agent 3.1/32.783
| MIME-Version: 1.0
| Content-Type: text/plain; charset=us-ascii
| Content-Transfer-Encoding: 7bit
| Lines: 3
| X-Trace:
sv3-M2778cOofvv+7pUouc91nYf8amNi1MIP1TrvhT7vCSEChTreHr 8ihFA6wrhX9uMtZIzF80Dh
UvABJDm!rXz2Kd8S61nBVIeGz2LeRDM4s8pTceLWMXkb8LUz0w Ivk8HzLW1x1oeaFRL5bemj1PDc
IA==
| X-Complaints-To: ab***@giganews.com
| X-DMCA-Notifications: http://www.giganews.com/info/dmca.html
| X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
| X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your
complaint properly
| X-Postfilter: 1.3.32
| Path:
TK2MSFTNGXA02.phx.gbl!TK2MSFTNGP08.phx.gbl!newsfee d00.sul.t-online.de!t-onli
ne.de!border2.nntp.dca.giganews.com!border1.nntp.d ca.giganews.com!nntp.gigan
ews.com!local01.nntp.dca.giganews.com!news.giganew s.com.POSTED!not-for-mail
| Xref: TK2MSFTNGXA02.phx.gbl
microsoft.public.dotnet.framework.aspnet:371159
| X-Tomcat-NG: microsoft.public.dotnet.framework.aspnet
|
| Ouch! That's an annoying limitation of the "builtin" http server. Thanx
for the info.
|
| - Mark
|

Jan 17 '06 #4

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

0
by: James Martin | last post by:
With the .NET Framework version 1.1, the following web.config code causes all of the html/aspx relative path references to fail: <sessionState mode="InProc" cookieless="true" timeout="20"/> ...
3
by: Scott | last post by:
Hello, we are having problems displaying non-aspx files (images, style sheets) since we have upgraded to the 1.1 framework when using a cookieless session (sessionID in the url). Check out...
2
by: Tom Pester | last post by:
I experimented/researched cookieless sessions and tried it on my website. I expected the switch to cookieless sessions to be transparent but this isn' t the case at all: 1) Forms based...
4
by: Bernie Raffe | last post by:
When I change the 'cookieless' flag in the WebConfig file to true, everything works fine on my local PC, but the images fail to appear when using the remote server. I specify my images...
2
by: rk325 | last post by:
I have a question about cookies & browser permissions and turning off cookies when creating a web site (cookieless mode in web.config). I have a web site that of course uses Session variables....
0
by: Chris Gill | last post by:
I'm trying to use cookieless sessions in asp.net using the InProc mode (for various reasons it is not desirable for us to use the other modes if it is possible to avoid them). My problem revolves...
1
by: Trevor | last post by:
Hi I have built a site with some secure pages, in a subdirectory with anonymous access off, and cookeless forms security. I thought that this would be accessible to all without the need for...
1
by: Mark Olbert | last post by:
I'm building an ASPNET2 website which uses forms authentication but does not use the Microsoft-supplied membership providers (mostly because I don't want to create my own provider at this point, and...
2
by: ravisingh11 | last post by:
<authentication mode="Forms"> <forms loginUrl="Login.aspx" protection="All" timeout="30" cookieless="AutoDetect" /> </authentication> Over here we can specify cookiless to be auto detect so...
1
by: CloudSolutions | last post by:
Introduction: For many beginners and individual users, requiring a credit card and email registration may pose a barrier when starting to use cloud servers. However, some cloud server providers now...
0
by: Faith0G | last post by:
I am starting a new it consulting business and it's been a while since I setup a new website. Is wordpress still the best web based software for hosting a 5 page website? The webpages will be...
0
by: taylorcarr | last post by:
A Canon printer is a smart device known for being advanced, efficient, and reliable. It is designed for home, office, and hybrid workspace use and can also be used for a variety of purposes. However,...
0
by: aa123db | last post by:
Variable and constants Use var or let for variables and const fror constants. Var foo ='bar'; Let foo ='bar';const baz ='bar'; Functions function $name$ ($parameters$) { } ...
0
by: ryjfgjl | last post by:
In our work, we often receive Excel tables with data in the same format. If we want to analyze these data, it can be difficult to analyze them because the data is spread across multiple Excel files...
0
by: emmanuelkatto | last post by:
Hi All, I am Emmanuel katto from Uganda. I want to ask what challenges you've faced while migrating a website to cloud. Please let me know. Thanks! Emmanuel
0
BarryA
by: BarryA | last post by:
What are the essential steps and strategies outlined in the Data Structures and Algorithms (DSA) roadmap for aspiring data scientists? How can individuals effectively utilize this roadmap to progress...
1
by: nemocccc | last post by:
hello, everyone, I want to develop a software for my android phone for daily needs, any suggestions?
0
by: Hystou | last post by:
There are some requirements for setting up RAID: 1. The motherboard and BIOS support RAID configuration. 2. The motherboard has 2 or more available SATA protocol SSD/HDD slots (including MSATA, M.2...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.