forms auth - session timeout - multi domains - POST values

Ask a Question related to ASP.NET Security, Design and Development.

  1. #1

    Default forms auth - session timeout - multi domains - POST values

    I have several questions.

    1) Does forms authentication store and re-send data intended for the
    secured page via a post request during its redirection to the login page?

    For example, I am a authenticated user filling out a form. I leave my
    computer for a bit and my session times out. I come back and submit the
    form. How is this handled within the forms authentication model?

    2) I have multiple domain names. I persist cookies in the browser once for
    each domain. The user authenticates on [url]www.thisdomain.com[/url] but then requests
    a resource on [url]www.thatdomain.com[/url]. Will I be able to access the users
    authentication status?
    Larry Foulkrod Guest

  2. Similar Questions and Discussions

    1. Session Variables over Different Domains
      Did you guys ever find an answer to this problem? I am having the same issue. It should be so simple, but not even passing the jsessionid to the url...
    2. Forms Auth Info passed to Windows Auth?
      The requirement is to build an ASP.Net intranet application, so external users can log in to the main web portal via forms authentication, using...
    3. WS using HTTP-POST auth
      How can I call web service using HTTP-POST in asp.net where on the server side is windows authentification required? thank you, Jure
    4. Configuring Windows Auth & Forms Auth in Asp.Net
      Configuring Windows Auth & Forms Auth in Asp.Ne Hi, I've configured a web app to use windows authentication and also set up two separate...
    5. Forms Auth Timeout and Form Data Preservation
      Does anyone know if form data, stuff that the user has typed into a textbox or selected from a dropdown, is preserved when they have to re-login...
  3. #2

    Default Re: forms auth - session timeout - multi domains - POST values

    > For example, I am a authenticated user filling out a form. I leave my
    > computer for a bit and my session times out. I come back and submit
    > the form. How is this handled within the forms authentication model?
    Forms Authentication uses a different cookie than Session, so they are tracked
    independantly. In the scenario you describe, the Session will be gone but
    they will have logged in (barring assumptions in your code about the presence
    of Session that prevents this).
    > 2) I have multiple domain names. I persist cookies in the browser
    > once for each domain. The user authenticates on [url]www.thisdomain.com[/url]
    > but then requests a resource on [url]www.thatdomain.com[/url]. Will I be able to
    > access the users authentication status?
    Cookies are scoped to the domain, so an ASP.NET authentication cookie issued
    by one won't be visible by another. They'll have to somehow authenticate
    on the second domain to have that cookie issued.

    -Brock
    DevelopMentor
    [url]http://staff.develop.com/ballen[/url]



    Brock Allen Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139