473,545 Members | 2,543 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

pass login to application

how can pass the login (security info) to secondary application?
ASP.NET 1.1

user login to application 1(app1.myapp.co m) with their username and
password, then they have a link to application 2 (app2.myapp.com ) and I want
to pass the authentication of application 2 with backend process.

Also, security issue is first priority.

Thanks in advanced.
Apr 5 '06 #1
1 2108
What I have done in the past was use a "public" and "private" token to pass
a user around from application to application.

When a user clicks on a link that leads to another web application, I first
create a private token (a guid if you will) and store it in some common
storage (SQL Server). Then I take the hash of the private token (along with
the username, referring page url) and pass it as an argument to the website.
The tokens have short lifespans and will timeout after say 10 seconds.

I use both AD and Custom Rolled Security accounts. NT Accounts would be
internal employees that are mainly managing content and providing minimal
data entry. Custom Security accounts (Simply a series of tables in a SQL
server) are B2B users and registered customers/affiliates. There is a
private web services sitting just inside the DMZ to manage both security
authentication modes and all data manipulation. The public web server(s)
is/are merely the interface and conduit.

In order for there to be acceptance of the "credential s", the hash must
match, the username must match that which is stored with the private token,
the referring page url must match the value that was passed along. If the
authentication fails, the user is challenged with the regular login screen.
Because of the NT accounts, their password is cached (encrypted) in a SQL
table so that they may request data from the private web service and provide
valid credentials.

It seems pretty solid to me and has been running since 2002 servicing 1,200
users, 150-300 concurrently during peak hours. It has passed every audit
and inspection thrown at us from the likes (at the time) Anderson
Consulting, Burbee, and over a dozen major pharmaceutical companies (I am
not allowed to devulge names).

The solution supports 23 distinct web applications (ASP and ASP.Net)
spanning 2 public web servers, 2 private web services servers, 4 Citrix
servers, IP*Switch's Webmail solution, Outlook Web Access. All of this
access is provided via a single login screen, a virtual desktop if you will.
Granted some customizations were made in Webmail and OWA to complete the
circle.

I only wish that VS'05 was out when I began the development using VS'02. At
least now I have a lot more experience to barrow from when I remodel it.
AJAX?, heck it used to be just an Div Tag wrapping an IFrame with some
javascript thrown in to make a progress bar and to wait for the response.
Web services used to be Http requests, then some elaborate SOAP, then DIME.
Man have we come far since 1995 IIS 2.0 and Navigator, let alone Prodigy's
rate increase marking the death of BBS's and gopher's text being replaced by
hyper text in '93.

I hope this helps.
"beachboy" <jp********@yah oo.com.hk> wrote in message
news:uW******** ******@TK2MSFTN GP05.phx.gbl...
how can pass the login (security info) to secondary application?
ASP.NET 1.1

user login to application 1(app1.myapp.co m) with their username and
password, then they have a link to application 2 (app2.myapp.com ) and I
want to pass the authentication of application 2 with backend process.

Also, security issue is first priority.

Thanks in advanced.

Apr 5 '06 #2

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

1
2529
by: Joe | last post by:
I have 3 servers server1: http://server1/login.asp, http://server1/page1.as server2: http://server2/login.asp, http://server2/page1.as server3: http://server3/login.asp, http://server3/page1.as When the user login the username and password in http://server1/login.asp, and clic submit button, it will go to http://server1/page1.asp if the...
9
1958
by: Paul | last post by:
What I am trying to do is as follows. I have a page with 3 links,that direct the user to 3 different pages when selected after login. So all link selections will first direct the user to a login page. Once the user logs in then they are directed to the appropriate link. So for all 3 links they all go to a login page, but each link must pass...
3
8406
by: cmueller | last post by:
Hey all - I'm in a bit of a bind concerning web services and integrated authentication. I'll give you a little background as to what I'm trying to do ... I have a client application that calls a web service. The web service uses integrated windows authentication (with identity impersonation = true in Web.Config) with anonymous...
10
4489
by: et | last post by:
I have an asp.net program that uses a connection string, using integrated security to connect to a sql database. It runs fine on one server, but the other server gives me the error that "Login failed for user "NT AUTHORITY/ANONYMOUS LOGON". Why would this be? There is no reason it should even be trying to login to using NT...
3
1302
by: Hei | last post by:
Hi All, i using .showdialog to show a child form for user input some data, and i wand to pass back these data to the parent form. how can i achieve this? thx. Hei.
1
1264
by: beachboy | last post by:
how can pass the login (security info) to secondary application? ASP.NET 1.1 user login to application 1(app1.myapp.com) with their username and password, then they have a link to application 2 (app2.myapp.com) and I want to pass the authentication of application 2 with backend process. Also, security issue is first priority. Thanks in...
1
3049
by: xcelmind | last post by:
Hello Dev. Guru, I want to at this time introduce myself. I am Stanley Ojadovwa by name. I’m a freelance and a newbie in web application development. I’m currently using ASP as my application server technology with Microsoft access as my database source. Just as I have introduced myself, I’m a newbie in web application development....
0
1493
by: HomerS007 | last post by:
Hi, I'm using asp.net 2.0 and sql server 2000 for my first ever project. On one of the page in the application, I want to limit what the user can see based on his/her login. It's a page that has sensitive personal info like social security number and I only want user to see their own information and no one else. Can anybody please tell me...
2
2383
by: adam.waterfield | last post by:
Maybe someone could help me a little here. On a project I am working on, we have some LDAP authentication to Active Directory which allows users to login to our application - this is fine. When accessing this application from off campus, they routinely get this login window confused with the one they login to Exchange Sever with for their...
0
7464
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However, people are often confused as to whether an ONU can Work As a Router. In this blog post, we’ll explore What is ONU, What Is Router, ONU & Router’s main...
0
7805
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven tapestry of website design and digital marketing. It's not merely about having a website; it's about crafting an immersive digital experience that...
0
7751
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each protocol has its own unique characteristics and advantages, but as a user who is planning to build a smart home system, I am a bit confused by the...
0
5968
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing, and deployment—without human intervention. Imagine an AI that can take a project description, break it down, write the code, debug it, and then...
1
5323
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new presenter, Adolph Dupré who will be discussing some powerful techniques for using class modules. He will explain when you may want to use classes...
0
3440
by: adsilva | last post by:
A Windows Forms form does not have the event Unload, like VB6. What one acts like?
1
1874
by: 6302768590 | last post by:
Hai team i want code for transfer the data from one system to another through IP address by using C# our system has to for every 5mins then we have to update the data what the data is updated we have to send another system
1
1012
muto222
by: muto222 | last post by:
How can i add a mobile payment intergratation into php mysql website.
0
700
bsmnconsultancy
by: bsmnconsultancy | last post by:
In today's digital era, a well-designed website is crucial for businesses looking to succeed. Whether you're a small business owner or a large corporation in Toronto, having a strong online presence can significantly impact your brand's success. BSMN Consultancy, a leader in Website Development in Toronto offers valuable insights into creating...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.