Friday, March 16, 2012
Persistent connections possible in ASP.Net?
most browsers support server push (which is really client pull), but its of
limited use. you'd have to update the asp.net timeouts. also its doesn't
scale well. a codebehind background thread could open a persistent
connection easily.
-- bruce (sqlwork.com)
"Jim Hubbard" <reply@.groups.please> wrote in message
news:IJWdnRcZWrqrNG3cRVn-3Q@.giganews.com...
| Is it possible to have persistent connections in ASP.Net?
|
|
Jim Hubbard wrote:
> Is it possible to have persistent connections in ASP.Net?
This is nothing to with ASP.NET. It's a web server feature. And yes,
IIS supports persistent connections.
Cheers,
http://www.joergjooss.de
mailto:news-reply@.joergjooss.de
Persistent connections possible in ASP.Net?
most browsers support server push (which is really client pull), but its of
limited use. you'd have to update the asp.net timeouts. also its doesn't
scale well. a codebehind background thread could open a persistent
connection easily.
-- bruce (sqlwork.com)
"Jim Hubbard" <reply@.groups.please> wrote in message
news:IJWdnRcZWrqrNG3cRVn-3Q@.giganews.com...
| Is it possible to have persistent connections in ASP.Net?
|
|
Jim Hubbard wrote:
> Is it possible to have persistent connections in ASP.Net?
This is nothing to with ASP.NET. It's a web server feature. And yes,
IIS supports persistent connections.
Cheers,
--
http://www.joergjooss.de
mailto:news-reply@.joergjooss.de
Persistent Cookies
I didn't get any response in "Security" forum hence posting here again.
I am having problem with persistent cookies. Even after setting
"CreatePersistentCookie" to true in "FormsAuthentication.SetAuthCookie" I'm
being logged out after the specifed timeout provided in "forms"
element of web.config.
I read somewhere that lifetime of persistent cookies depend on the timeout
attribute on the forms authentcation node. If I have to enter a timeout of
days/weeks then it doesnt really make sense to make my cookie persist in
this fashion, that defies the purpose of persistent cookies.
Any insights welcome
Thanks
SanchitaYou miss the purpose of persistant cookies. They are not used for session
management, they are used for authentication.
A persistent cookie is designed to allow the user to access a secured site
without having to log in again when he hits the site the second time. It
persists the authentication on the client side so it is sent with the
header. The system then automatically logs him in.
Session timeout is a part of your application. While the cookie can "re-log
on" the user if he times out, it cannot change the timeout behavior on the
server just because the user has a cookie.
For the record, you should NOT increase timeout to days. That defeats the
purpose of session management. What you can do is kick the user back to the
start page and abandon session, forcing the timeout. You then provide a link
on the timeout page. This can be a dynamic link back to where he was
working, if you desire. The user will then be logged back in, as the cookie
is there.
This may not be what you envision and make you think you want to increase
session time until the year 2010. Here is why. The session timeout is how
long the server keeps objects in session, meaning in memory on the server.
You set a really long timeout, say two weeks out. That session is now open
for two weeks. User's computer crashes and he opens the browser and hits
your site. You now have 2 two-week sessions for one user. After some work,
the user shuts down and then opens the browser again and hits the site. You
now have 3 two-week sessions for one user. This can go on until you use all
of the memory on the server with just a couple of users.
--
Gregory A. Beamer
MVP; MCP: +I, SE, SD, DBA
*********************************************
Think outside the box!
*********************************************
"sanchita" <sanchita@.fareportal.comwrote in message
news:OSj$Xv%23bHHA.1244@.TK2MSFTNGP04.phx.gbl...
Quote:
Originally Posted by
Hello everyone,
>
I didn't get any response in "Security" forum hence posting here again.
>
I am having problem with persistent cookies. Even after setting
"CreatePersistentCookie" to true in "FormsAuthentication.SetAuthCookie"
I'm
being logged out after the specifed timeout provided in "forms"
element of web.config.
>
I read somewhere that lifetime of persistent cookies depend on the timeout
attribute on the forms authentcation node. If I have to enter a timeout of
days/weeks then it doesnt really make sense to make my cookie persist in
this fashion, that defies the purpose of persistent cookies.
>
Any insights welcome
Thanks
Sanchita
>
Hi sanchita,
This has been a change in ASP.NET 2.0. If you don't specify
CreatePersistantCookie the cookie times out. If you do, then the timeout
value is what determines the cookie timeout even if you create a persistent
cookie.
This differs from ASP.NET 1.x which created a cookie with a long expiration
date - in 2.0 the expiration date is based on the timeout.
IOW, you need to set thte timeout value to a large number if you want a true
persistent cookie.
+++ Rick --
--
Rick Strahl
West Wind Technologies
www.west-wind.com/weblog
"sanchita" <sanchita@.fareportal.comwrote in message
news:OSj$Xv%23bHHA.1244@.TK2MSFTNGP04.phx.gbl...
Quote:
Originally Posted by
Hello everyone,
>
I didn't get any response in "Security" forum hence posting here again.
>
I am having problem with persistent cookies. Even after setting
"CreatePersistentCookie" to true in "FormsAuthentication.SetAuthCookie"
I'm
being logged out after the specifed timeout provided in "forms"
element of web.config.
>
I read somewhere that lifetime of persistent cookies depend on the timeout
attribute on the forms authentcation node. If I have to enter a timeout of
days/weeks then it doesnt really make sense to make my cookie persist in
this fashion, that defies the purpose of persistent cookies.
>
Any insights welcome
Thanks
Sanchita
>
Yes I know that they arent used for session management. Since persistent
cookies arent working the way they were in asp.net 1.1, wherein what used to
happen was the framework itself had set the timeout for a persistent cookie
for days, we didn't have a control over it. However in asp.net 2.0 we can
set the timeout for persistent cookies in our configuration. But the funny
thing is no matter if you want the cookie to be persistent or
non-persistent, both will acquire this timeout value. So it leaves me no
choice but to set one. Scott Gutherie from Microsoft also verifed on this to
us.
Although I'm working out my options and not just setting the timeout value
to a huge number. For the record I'm using Dotnetnuke 2.4 and facing this
problem since I shifted to asp.net 2.0. However my Team leader tells me that
in DNN 4.0 persistent cookies work fine despite the default timeout.
Thanks
Sanchita
"Cowboy (Gregory A. Beamer)" <NoSpamMgbworld@.comcast.netNoSpamMwrote in
message news:ADE74ED7-274F-4938-A1BC-50C9A3C38779@.microsoft.com...
Quote:
Originally Posted by
You miss the purpose of persistant cookies. They are not used for session
management, they are used for authentication.
>
A persistent cookie is designed to allow the user to access a secured site
without having to log in again when he hits the site the second time. It
persists the authentication on the client side so it is sent with the
header. The system then automatically logs him in.
>
Session timeout is a part of your application. While the cookie can
"re-log on" the user if he times out, it cannot change the timeout
behavior on the server just because the user has a cookie.
>
For the record, you should NOT increase timeout to days. That defeats the
purpose of session management. What you can do is kick the user back to
the start page and abandon session, forcing the timeout. You then provide
a link on the timeout page. This can be a dynamic link back to where he
was working, if you desire. The user will then be logged back in, as the
cookie is there.
>
This may not be what you envision and make you think you want to increase
session time until the year 2010. Here is why. The session timeout is how
long the server keeps objects in session, meaning in memory on the server.
You set a really long timeout, say two weeks out. That session is now open
for two weeks. User's computer crashes and he opens the browser and hits
your site. You now have 2 two-week sessions for one user. After some work,
the user shuts down and then opens the browser again and hits the site.
You now have 3 two-week sessions for one user. This can go on until you
use all of the memory on the server with just a couple of users.
>
--
Gregory A. Beamer
MVP; MCP: +I, SE, SD, DBA
>
*********************************************
Think outside the box!
*********************************************
"sanchita" <sanchita@.fareportal.comwrote in message
news:OSj$Xv%23bHHA.1244@.TK2MSFTNGP04.phx.gbl...
Quote:
Originally Posted by
>Hello everyone,
>>
>I didn't get any response in "Security" forum hence posting here again.
>>
>I am having problem with persistent cookies. Even after setting
>"CreatePersistentCookie" to true in "FormsAuthentication.SetAuthCookie"
>I'm
>being logged out after the specifed timeout provided in "forms"
>element of web.config.
>>
>I read somewhere that lifetime of persistent cookies depend on the
>timeout
>attribute on the forms authentcation node. If I have to enter a timeout
>of
>days/weeks then it doesnt really make sense to make my cookie persist in
>this fashion, that defies the purpose of persistent cookies.
>>
>Any insights welcome
>Thanks
>Sanchita
>>
>
Persistent Cookie not working
them to login again (assuming they checked "remember me" on the login
control).
I've tried increasing the timeouts to 3000000+ but it still requires
users to login if the session times out (roughly 30 minutes or so).
What am I missing? Thanks!
I do have web.configs to protect the "secure" directories:
<system.web>
<authorization>
<allow roles="Administrators" />
<deny roles="Users" />
<deny users="?" />
</authorization>
</system.web>
Here is the relevent site web.config section:
<authentication mode="Forms">
<forms loginUrl="main/Login.aspx" defaultUrl="main/Login.aspx"
cookieless="UseCookies" timeout="5000000" />
</authentication>
<membership defaultProvider="CrossroadsMembershipSqlProvider" >
<providers>
<add name="CrossroadsMembershipSqlProvider"
type="System.Web.Security.SqlMembershipProvider, System.Web,
Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
connectionStringName="LocalSqlServer" enablePasswordRetrieval="false"
enablePasswordReset="true" requiresQuestionAndAnswer="false"
applicationName="Crossroads" requiresUniqueEmail="true"
passwordFormat="Clear" minRequiredPasswordLength="5"
minRequiredNonalphanumericCharacters="0"/>
</providers>
</membership>
<roleManager enabled="true" cacheRolesInCookie="true"
defaultProvider="CrossroadsRoleManagerSqlProvider"
cookieName=".ASPXROLES" cookiePath="/" cookieTimeout="300000000"
cookieRequireSSL="false" cookieSlidingExpiration="true"
createPersistentCookie="true" cookieProtection="All" >
<providers>
<add name="CrossroadsRoleManagerSqlProvider"
type="System.Web.Security.SqlRoleProvider, System.Web, Version=2.0.0.0,
Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
connectionStringName="LocalSqlServer" applicationName="Crossroads"/>
</providers>
</roleManager>A discussion i did lately, a session has nearly nothing to do with
authentication.
Especially when used with persistant cookies.
It's likely you made a flaw by making the user depending on some dumb
session variable.
Whenit expires you could follow the global.asax events to track if indeed
the authentication is still valid..
In some cases the session is (imo mis-) used to hold a non-persistant user
(cookieless or similar).
So in that case authentication is depending on the session-id.
<jrhea2006@.kellogg.northwestern.edu> schreef in bericht
news:1140218394.253371.152540@.o13g2000cwo.googlegroups.com...
>I want my site to remember users when they come back without requiring
> them to login again (assuming they checked "remember me" on the login
> control).
> I've tried increasing the timeouts to 3000000+ but it still requires
> users to login if the session times out (roughly 30 minutes or so).
> What am I missing? Thanks!
> I do have web.configs to protect the "secure" directories:
> <system.web>
> <authorization>
> <allow roles="Administrators" />
> <deny roles="Users" />
> <deny users="?" />
> </authorization>
> </system.web>
> Here is the relevent site web.config section:
> <authentication mode="Forms">
> <forms loginUrl="main/Login.aspx" defaultUrl="main/Login.aspx"
> cookieless="UseCookies" timeout="5000000" />
> </authentication>
> <membership defaultProvider="CrossroadsMembershipSqlProvider" >
> <providers>
> <add name="CrossroadsMembershipSqlProvider"
> type="System.Web.Security.SqlMembershipProvider, System.Web,
> Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
> connectionStringName="LocalSqlServer" enablePasswordRetrieval="false"
> enablePasswordReset="true" requiresQuestionAndAnswer="false"
> applicationName="Crossroads" requiresUniqueEmail="true"
> passwordFormat="Clear" minRequiredPasswordLength="5"
> minRequiredNonalphanumericCharacters="0"/>
> </providers>
> </membership>
> <roleManager enabled="true" cacheRolesInCookie="true"
> defaultProvider="CrossroadsRoleManagerSqlProvider"
> cookieName=".ASPXROLES" cookiePath="/" cookieTimeout="300000000"
> cookieRequireSSL="false" cookieSlidingExpiration="true"
> createPersistentCookie="true" cookieProtection="All" >
> <providers>
> <add name="CrossroadsRoleManagerSqlProvider"
> type="System.Web.Security.SqlRoleProvider, System.Web, Version=2.0.0.0,
> Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
> connectionStringName="LocalSqlServer" applicationName="Crossroads"/>
> </providers>
> </roleManager>
>
HOW annoying, MULTIPOST with all the news group resolve errors i get!
<jrhea2006@.kellogg.northwestern.edu> schreef in bericht
news:1140218394.253371.152540@.o13g2000cwo.googlegroups.com...
>I want my site to remember users when they come back without requiring
> them to login again (assuming they checked "remember me" on the login
> control).
> I've tried increasing the timeouts to 3000000+ but it still requires
> users to login if the session times out (roughly 30 minutes or so).
> What am I missing? Thanks!
> I do have web.configs to protect the "secure" directories:
> <system.web>
> <authorization>
> <allow roles="Administrators" />
> <deny roles="Users" />
> <deny users="?" />
> </authorization>
> </system.web>
> Here is the relevent site web.config section:
> <authentication mode="Forms">
> <forms loginUrl="main/Login.aspx" defaultUrl="main/Login.aspx"
> cookieless="UseCookies" timeout="5000000" />
> </authentication>
> <membership defaultProvider="CrossroadsMembershipSqlProvider" >
> <providers>
> <add name="CrossroadsMembershipSqlProvider"
> type="System.Web.Security.SqlMembershipProvider, System.Web,
> Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
> connectionStringName="LocalSqlServer" enablePasswordRetrieval="false"
> enablePasswordReset="true" requiresQuestionAndAnswer="false"
> applicationName="Crossroads" requiresUniqueEmail="true"
> passwordFormat="Clear" minRequiredPasswordLength="5"
> minRequiredNonalphanumericCharacters="0"/>
> </providers>
> </membership>
> <roleManager enabled="true" cacheRolesInCookie="true"
> defaultProvider="CrossroadsRoleManagerSqlProvider"
> cookieName=".ASPXROLES" cookiePath="/" cookieTimeout="300000000"
> cookieRequireSSL="false" cookieSlidingExpiration="true"
> createPersistentCookie="true" cookieProtection="All" >
> <providers>
> <add name="CrossroadsRoleManagerSqlProvider"
> type="System.Web.Security.SqlRoleProvider, System.Web, Version=2.0.0.0,
> Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
> connectionStringName="LocalSqlServer" applicationName="Crossroads"/>
> </providers>
> </roleManager>
>
Thanks Edwin - great value add there.
I posted to the security thread and then in looking through the group
didn't see a lot of traffic so I thought I'd try my hand at the regular
aspnet group.
Is that OK or do I still get 20 lashes with a wet noodle?
>..or do I still get 20 lashes with a wet noodle?
Hmm, haven't thought about your punishment yet, but i expect i can have some
lashes myself so now and then :D
:)
<jrhea2006@.kellogg.northwestern.edu> schreef in bericht
news:1140272892.935793.9000@.z14g2000cwz.googlegroups.com...
> Thanks Edwin - great value add there.
> I posted to the security thread and then in looking through the group
> didn't see a lot of traffic so I thought I'd try my hand at the regular
> aspnet group.
> Is that OK or do I still get 20 lashes with a wet noodle?
>
Oops again!
That makes 40 lashes !
<jrhea2006@.kellogg.northwestern.edu> schreef in bericht
news:1140272892.935793.9000@.z14g2000cwz.googlegroups.com...
> Thanks Edwin - great value add there.
> I posted to the security thread and then in looking through the group
> didn't see a lot of traffic so I thought I'd try my hand at the regular
> aspnet group.
> Is that OK or do I still get 20 lashes with a wet noodle?
>
Persistent Cookie not working
them to login again (assuming they checked "remember me" on the login
control).
I've tried increasing the timeouts to 3000000+ but it still requires
users to login if the session times out (roughly 30 minutes or so).
What am I missing? Thanks!
I do have web.configs to protect the "secure" directories:
<system.web>
<authorization>
<allow roles="Administrators" />
<deny roles="Users" />
<deny users="?" />
</authorization>
</system.web
Here is the relevent site web.config section:
<authentication mode="Forms">
<forms loginUrl="main/Login.aspx" defaultUrl="main/Login.aspx"
cookieless="UseCookies" timeout="5000000" />
</authentication>
<membership defaultProvider="CrossroadsMembershipSqlProvider" >
<providers>
<add name="CrossroadsMembershipSqlProvider"
type="System.Web.Security.SqlMembershipProvider, System.Web,
Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
connectionStringName="LocalSqlServer" enablePasswordRetrieval="false"
enablePasswordReset="true" requiresQuestionAndAnswer="false"
applicationName="Crossroads" requiresUniqueEmail="true"
passwordFormat="Clear" minRequiredPasswordLength="5"
minRequiredNonalphanumericCharacters="0"/>
</providers>
</membership>
<roleManager enabled="true" cacheRolesInCookie="true"
defaultProvider="CrossroadsRoleManagerSqlProvider"
cookieName=".ASPXROLES" cookiePath="/" cookieTimeout="300000000"
cookieRequireSSL="false" cookieSlidingExpiration="true"
createPersistentCookie="true" cookieProtection="All" >
<providers>
<add name="CrossroadsRoleManagerSqlProvider"
type="System.Web.Security.SqlRoleProvider, System.Web, Version=2.0.0.0,
Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
connectionStringName="LocalSqlServer" applicationName="Crossroads"/>
</providers>
</roleManagerA discussion i did lately, a session has nearly nothing to do with
authentication.
Especially when used with persistant cookies.
It's likely you made a flaw by making the user depending on some dumb
session variable.
Whenit expires you could follow the global.asax events to track if indeed
the authentication is still valid..
In some cases the session is (imo mis-) used to hold a non-persistant user
(cookieless or similar).
So in that case authentication is depending on the session-id.
<jrhea2006@.kellogg.northwestern.edu> schreef in bericht
news:1140218394.253371.152540@.o13g2000cwo.googlegr oups.com...
>I want my site to remember users when they come back without requiring
> them to login again (assuming they checked "remember me" on the login
> control).
> I've tried increasing the timeouts to 3000000+ but it still requires
> users to login if the session times out (roughly 30 minutes or so).
> What am I missing? Thanks!
> I do have web.configs to protect the "secure" directories:
> <system.web>
> <authorization>
> <allow roles="Administrators" />
> <deny roles="Users" />
> <deny users="?" />
> </authorization>
> </system.web>
> Here is the relevent site web.config section:
> <authentication mode="Forms">
> <forms loginUrl="main/Login.aspx" defaultUrl="main/Login.aspx"
> cookieless="UseCookies" timeout="5000000" />
> </authentication>
> <membership defaultProvider="CrossroadsMembershipSqlProvider" >
> <providers>
> <add name="CrossroadsMembershipSqlProvider"
> type="System.Web.Security.SqlMembershipProvider, System.Web,
> Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
> connectionStringName="LocalSqlServer" enablePasswordRetrieval="false"
> enablePasswordReset="true" requiresQuestionAndAnswer="false"
> applicationName="Crossroads" requiresUniqueEmail="true"
> passwordFormat="Clear" minRequiredPasswordLength="5"
> minRequiredNonalphanumericCharacters="0"/>
> </providers>
> </membership>
> <roleManager enabled="true" cacheRolesInCookie="true"
> defaultProvider="CrossroadsRoleManagerSqlProvider"
> cookieName=".ASPXROLES" cookiePath="/" cookieTimeout="300000000"
> cookieRequireSSL="false" cookieSlidingExpiration="true"
> createPersistentCookie="true" cookieProtection="All" >
> <providers>
> <add name="CrossroadsRoleManagerSqlProvider"
> type="System.Web.Security.SqlRoleProvider, System.Web, Version=2.0.0.0,
> Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
> connectionStringName="LocalSqlServer" applicationName="Crossroads"/>
> </providers>
> </roleManager
HOW annoying, MULTIPOST with all the news group resolve errors i get!
<jrhea2006@.kellogg.northwestern.edu> schreef in bericht
news:1140218394.253371.152540@.o13g2000cwo.googlegr oups.com...
>I want my site to remember users when they come back without requiring
> them to login again (assuming they checked "remember me" on the login
> control).
> I've tried increasing the timeouts to 3000000+ but it still requires
> users to login if the session times out (roughly 30 minutes or so).
> What am I missing? Thanks!
> I do have web.configs to protect the "secure" directories:
> <system.web>
> <authorization>
> <allow roles="Administrators" />
> <deny roles="Users" />
> <deny users="?" />
> </authorization>
> </system.web>
> Here is the relevent site web.config section:
> <authentication mode="Forms">
> <forms loginUrl="main/Login.aspx" defaultUrl="main/Login.aspx"
> cookieless="UseCookies" timeout="5000000" />
> </authentication>
> <membership defaultProvider="CrossroadsMembershipSqlProvider" >
> <providers>
> <add name="CrossroadsMembershipSqlProvider"
> type="System.Web.Security.SqlMembershipProvider, System.Web,
> Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
> connectionStringName="LocalSqlServer" enablePasswordRetrieval="false"
> enablePasswordReset="true" requiresQuestionAndAnswer="false"
> applicationName="Crossroads" requiresUniqueEmail="true"
> passwordFormat="Clear" minRequiredPasswordLength="5"
> minRequiredNonalphanumericCharacters="0"/>
> </providers>
> </membership>
> <roleManager enabled="true" cacheRolesInCookie="true"
> defaultProvider="CrossroadsRoleManagerSqlProvider"
> cookieName=".ASPXROLES" cookiePath="/" cookieTimeout="300000000"
> cookieRequireSSL="false" cookieSlidingExpiration="true"
> createPersistentCookie="true" cookieProtection="All" >
> <providers>
> <add name="CrossroadsRoleManagerSqlProvider"
> type="System.Web.Security.SqlRoleProvider, System.Web, Version=2.0.0.0,
> Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
> connectionStringName="LocalSqlServer" applicationName="Crossroads"/>
> </providers>
> </roleManager
Thanks Edwin - great value add there.
I posted to the security thread and then in looking through the group
didn't see a lot of traffic so I thought I'd try my hand at the regular
aspnet group.
Is that OK or do I still get 20 lashes with a wet noodle?
>..or do I still get 20 lashes with a wet noodle?
Hmm, haven't thought about your punishment yet, but i expect i can have some
lashes myself so now and then :D
:)
<jrhea2006@.kellogg.northwestern.edu> schreef in bericht
news:1140272892.935793.9000@.z14g2000cwz.googlegrou ps.com...
> Thanks Edwin - great value add there.
> I posted to the security thread and then in looking through the group
> didn't see a lot of traffic so I thought I'd try my hand at the regular
> aspnet group.
> Is that OK or do I still get 20 lashes with a wet noodle?
Oops again!
That makes 40 lashes !
<jrhea2006@.kellogg.northwestern.edu> schreef in bericht
news:1140272892.935793.9000@.z14g2000cwz.googlegrou ps.com...
> Thanks Edwin - great value add there.
> I posted to the security thread and then in looking through the group
> didn't see a lot of traffic so I thought I'd try my hand at the regular
> aspnet group.
> Is that OK or do I still get 20 lashes with a wet noodle?
persistent cookies
Hi
I could not understand FWIW persistent cookies checkbox
I was logged in, cookie was already recorded but after closing and opening browser I'm still being redirected to sigin.aspx page
any help would be appreciated
Is it possible to post your Login Code where the cookie is being made ?sure, thanks
// Create a new ticket used for authentication
FormsAuthenticationTicket ticket = new FormsAuthenticationTicket(
1, // Ticket version
Username.Value, // Username associated with ticket
DateTime.Now, // Date/time issued
DateTime.Now.AddMinutes(30), // Date/time to expire
true, // "true" for a persistent user cookie
reader.GetString(0), // User-data, in this case the roles
FormsAuthentication.FormsCookiePath);// Path cookie valid for
Also I'm doing this into login button event handler:
...
FormsAuthentication.SetAuthCookie(txtUsername.Text, checkRemember.Checked);
...
Persistent Cookies
I didn't get any response in "Security" forum hence posting here again.
I am having problem with persistent cookies. Even after setting
"CreatePersistentCookie" to true in "FormsAuthentication.SetAuthCookie" I'm
being logged out after the specifed timeout provided in "forms"
element of web.config.
I read somewhere that lifetime of persistent cookies depend on the timeout
attribute on the forms authentcation node. If I have to enter a timeout of
days/w
this fashion, that defies the purpose of persistent cookies.
Any insights welcome
Thanks
SanchitaYou miss the purpose of persistant cookies. They are not used for session
management, they are used for authentication.
A persistent cookie is designed to allow the user to access a secured site
without having to log in again when he hits the site the second time. It
persists the authentication on the client side so it is sent with the
header. The system then automatically logs him in.
Session timeout is a part of your application. While the cookie can "re-log
on" the user if he times out, it cannot change the timeout behavior on the
server just because the user has a cookie.
For the record, you should NOT increase timeout to days. That defeats the
purpose of session management. What you can do is kick the user back to the
start page and abandon session, forcing the timeout. You then provide a link
on the timeout page. This can be a dynamic link back to where he was
working, if you desire. The user will then be logged back in, as the cookie
is there.
This may not be what you envision and make you think you want to increase
session time until the year 2010. Here is why. The session timeout is how
long the server keeps objects in session, meaning in memory on the server.
You set a really long timeout, say two w
for two w
your site. You now have 2 two-w
the user shuts down and then opens the browser again and hits the site. You
now have 3 two-w
of the memory on the server with just a couple of users.
Gregory A. Beamer
MVP; MCP: +I, SE, SD, DBA
****************************************
*****
Think outside the box!
****************************************
*****
"sanchita" <sanchita@.fareportal.com> wrote in message
news:OSj$Xv%23bHHA.1244@.TK2MSFTNGP04.phx.gbl...
> Hello everyone,
> I didn't get any response in "Security" forum hence posting here again.
> I am having problem with persistent cookies. Even after setting
> "CreatePersistentCookie" to true in "FormsAuthentication.SetAuthCookie"
> I'm
> being logged out after the specifed timeout provided in "forms"
> element of web.config.
> I read somewhere that lifetime of persistent cookies depend on the timeout
> attribute on the forms authentcation node. If I have to enter a timeout of
> days/w
> this fashion, that defies the purpose of persistent cookies.
> Any insights welcome
> Thanks
> Sanchita
>
Hi sanchita,
This has been a change in ASP.NET 2.0. If you don't specify
CreatePersistantCookie the cookie times out. If you do, then the timeout
value is what determines the cookie timeout even if you create a persistent
cookie.
This differs from ASP.NET 1.x which created a cookie with a long expiration
date - in 2.0 the expiration date is based on the timeout.
IOW, you need to set thte timeout value to a large number if you want a true
persistent cookie.
+++ Rick --
Rick Strahl
West Wind Technologies
www.west-wind.com/weblog
"sanchita" <sanchita@.fareportal.com> wrote in message
news:OSj$Xv%23bHHA.1244@.TK2MSFTNGP04.phx.gbl...
> Hello everyone,
> I didn't get any response in "Security" forum hence posting here again.
> I am having problem with persistent cookies. Even after setting
> "CreatePersistentCookie" to true in "FormsAuthentication.SetAuthCookie"
> I'm
> being logged out after the specifed timeout provided in "forms"
> element of web.config.
> I read somewhere that lifetime of persistent cookies depend on the timeout
> attribute on the forms authentcation node. If I have to enter a timeout of
> days/w
> this fashion, that defies the purpose of persistent cookies.
> Any insights welcome
> Thanks
> Sanchita
>
Yes I know that they arent used for session management. Since persistent
cookies arent working the way they were in asp.net 1.1, wherein what used to
happen was the framework itself had set the timeout for a persistent cookie
for days, we didn't have a control over it. However in asp.net 2.0 we can
set the timeout for persistent cookies in our configuration. But the funny
thing is no matter if you want the cookie to be persistent or
non-persistent, both will acquire this timeout value. So it leaves me no
choice but to set one. Scott Gutherie from Microsoft also verifed on this to
us.
Although I'm working out my options and not just setting the timeout value
to a huge number. For the record I'm using Dotnetnuke 2.4 and facing this
problem since I shifted to asp.net 2.0. However my Team leader tells me that
in DNN 4.0 persistent cookies work fine despite the default timeout.
Thanks
Sanchita
"Cowboy (Gregory A. Beamer)" <NoSpamMgbworld@.comcast.netNoSpamM> wrote in
message news:ADE74ED7-274F-4938-A1BC-50C9A3C38779@.microsoft.com...
> You miss the purpose of persistant cookies. They are not used for session
> management, they are used for authentication.
> A persistent cookie is designed to allow the user to access a secured site
> without having to log in again when he hits the site the second time. It
> persists the authentication on the client side so it is sent with the
> header. The system then automatically logs him in.
> Session timeout is a part of your application. While the cookie can
> "re-log on" the user if he times out, it cannot change the timeout
> behavior on the server just because the user has a cookie.
> For the record, you should NOT increase timeout to days. That defeats the
> purpose of session management. What you can do is kick the user back to
> the start page and abandon session, forcing the timeout. You then provide
> a link on the timeout page. This can be a dynamic link back to where he
> was working, if you desire. The user will then be logged back in, as the
> cookie is there.
> This may not be what you envision and make you think you want to increase
> session time until the year 2010. Here is why. The session timeout is how
> long the server keeps objects in session, meaning in memory on the server.
> You set a really long timeout, say two w
> for two w
> your site. You now have 2 two-w
> the user shuts down and then opens the browser again and hits the site.
> You now have 3 two-w
> use all of the memory on the server with just a couple of users.
> --
> Gregory A. Beamer
> MVP; MCP: +I, SE, SD, DBA
> ****************************************
*****
> Think outside the box!
> ****************************************
*****
> "sanchita" <sanchita@.fareportal.com> wrote in message
> news:OSj$Xv%23bHHA.1244@.TK2MSFTNGP04.phx.gbl...
>
Persistent Forms Authentication - and Session Variables
I'm doing an ASP.NET project which uses Persistent Forms Authentication
(i.e. once user logged in, they don't have to log in again). However Session
variables are erased after Session has timed out. So I need to re-populate
user specific session variables (such as user email, DOB, Full Name...etc)
when Session has ended.
But strangely, when I tried to do something like...
Dim strArrayUserInfo(10) as String
strArrayUserInfo(0) = drDataReader("FName").ToString
strArrayUserInfo(1) = drDataReader("LName").ToString
strArrayUserInfo(2) = drDataReader("Email").ToString
Session("UserInfoArray") = strArrayUserInfo
I get System.StackOverflowException. If I comment out that line, application
runs correctly but fail at the point where Session("UserInfoArray") is
accessed (i.e. Null Exception). So I de-comment the above code and I was
thrown System.StackOverflowException again.
What could be the problem? I was merely assigning a variable to Session
variable collection. Why ASP.NET throws System.StackOverflowException'
Thank you all in advance!!!!
Max"Max" <zero@.maxdot.com.com> wrote in message
news:ukaISv57EHA.2016@.TK2MSFTNGP15.phx.gbl...
> Hi All!
> I'm doing an ASP.NET project which uses Persistent Forms Authentication
> (i.e. once user logged in, they don't have to log in again). However
> Session variables are erased after Session has timed out. So I need to
> re-populate user specific session variables (such as user email, DOB, Full
> Name...etc) when Session has ended.
> But strangely, when I tried to do something like...
> Dim strArrayUserInfo(10) as String
> strArrayUserInfo(0) = drDataReader("FName").ToString
> strArrayUserInfo(1) = drDataReader("LName").ToString
> strArrayUserInfo(2) = drDataReader("Email").ToString
> Session("UserInfoArray") = strArrayUserInfo
> I get System.StackOverflowException. If I comment out that line,
> application runs correctly but fail at the point where
> Session("UserInfoArray") is accessed (i.e. Null Exception). So I
> de-comment the above code and I was thrown System.StackOverflowException
> again.
> What could be the problem? I was merely assigning a variable to Session
> variable collection. Why ASP.NET throws System.StackOverflowException'
I bet you have something else called "Session". Change the line to refer to
HttpContext.Current.Session and see if that's any better.
John Saunders
Hi John,
Thanks for the quick response! Unfortunately, I get the same error :(
Any ideas?
Max
"John Saunders" <johnwsaundersiii at hotmail.com> wrote in message
news:ew5r0757EHA.2016@.TK2MSFTNGP15.phx.gbl...
> "Max" <zero@.maxdot.com.com> wrote in message
> news:ukaISv57EHA.2016@.TK2MSFTNGP15.phx.gbl...
> I bet you have something else called "Session". Change the line to refer
> to HttpContext.Current.Session and see if that's any better.
> John Saunders
>
"Max" <zero@.maxdot.com.com> wrote in message
news:edEOMA67EHA.2552@.TK2MSFTNGP09.phx.gbl...
> Hi John,
> Thanks for the quick response! Unfortunately, I get the same error :(
Several ideas, none brilliant.
1) Simplify, simplify, simplify
1a) Instead of filling from the datareader, try setting the array elements
to constants. It's simpler.
1b) Try using Session("a"). It's simpler.
2) Are you setting all 10 elements of the array?
3) Turn Options Strict On.
John Saunders
> "John Saunders" <johnwsaundersiii at hotmail.com> wrote in message
> news:ew5r0757EHA.2016@.TK2MSFTNGP15.phx.gbl...
>
Hi John,
I tried reducing the Array length to 3 and still it didn't work. This is a
mystery and a nightmare.
Max
"John Saunders" <johnwsaundersiii at hotmail.com> wrote in message
news:uFWbK777EHA.2568@.TK2MSFTNGP10.phx.gbl...
> "Max" <zero@.maxdot.com.com> wrote in message
> news:edEOMA67EHA.2552@.TK2MSFTNGP09.phx.gbl...
> Several ideas, none brilliant.
> 1) Simplify, simplify, simplify
> 1a) Instead of filling from the datareader, try setting the array elements
> to constants. It's simpler.
> 1b) Try using Session("a"). It's simpler.
> 2) Are you setting all 10 elements of the array?
> 3) Turn Options Strict On.
> John Saunders
>
>
>
"Max" <zero@.maxdot.com.com> wrote in message
news:erNBq2U8EHA.2124@.TK2MSFTNGP14.phx.gbl...
> Hi John,
> I tried reducing the Array length to 3 and still it didn't work. This is a
> mystery and a nightmare.
Did you try using an array filled with constants? Did you try using
Session("a")? Have you turned Options Strict On?
John Saunders
> "John Saunders" <johnwsaundersiii at hotmail.com> wrote in message
> news:uFWbK777EHA.2568@.TK2MSFTNGP10.phx.gbl...
>
Persistent Forms Authentication - and Session Variables
I'm doing an ASP.NET project which uses Persistent Forms Authentication
(i.e. once user logged in, they don't have to log in again). However Session
variables are erased after Session has timed out. So I need to re-populate
user specific session variables (such as user email, DOB, Full Name...etc)
when Session has ended.
But strangely, when I tried to do something like...
Dim strArrayUserInfo(10) as String
strArrayUserInfo(0) = drDataReader("FName").ToString
strArrayUserInfo(1) = drDataReader("LName").ToString
strArrayUserInfo(2) = drDataReader("Email").ToString
Session("UserInfoArray") = strArrayUserInfo
I get System.StackOverflowException. If I comment out that line, application
runs correctly but fail at the point where Session("UserInfoArray") is
accessed (i.e. Null Exception). So I de-comment the above code and I was
thrown System.StackOverflowException again.
What could be the problem? I was merely assigning a variable to Session
variable collection. Why ASP.NET throws System.StackOverflowException??
Thank you all in advance!!!!
Max"Max" <zero@.maxdot.com.com> wrote in message
news:ukaISv57EHA.2016@.TK2MSFTNGP15.phx.gbl...
> Hi All!
> I'm doing an ASP.NET project which uses Persistent Forms Authentication
> (i.e. once user logged in, they don't have to log in again). However
> Session variables are erased after Session has timed out. So I need to
> re-populate user specific session variables (such as user email, DOB, Full
> Name...etc) when Session has ended.
> But strangely, when I tried to do something like...
> Dim strArrayUserInfo(10) as String
> strArrayUserInfo(0) = drDataReader("FName").ToString
> strArrayUserInfo(1) = drDataReader("LName").ToString
> strArrayUserInfo(2) = drDataReader("Email").ToString
> Session("UserInfoArray") = strArrayUserInfo
> I get System.StackOverflowException. If I comment out that line,
> application runs correctly but fail at the point where
> Session("UserInfoArray") is accessed (i.e. Null Exception). So I
> de-comment the above code and I was thrown System.StackOverflowException
> again.
> What could be the problem? I was merely assigning a variable to Session
> variable collection. Why ASP.NET throws System.StackOverflowException??
I bet you have something else called "Session". Change the line to refer to
HttpContext.Current.Session and see if that's any better.
John Saunders
Hi John,
Thanks for the quick response! Unfortunately, I get the same error :(
Any ideas?
Max
"John Saunders" <johnwsaundersiii at hotmail.com> wrote in message
news:ew5r0757EHA.2016@.TK2MSFTNGP15.phx.gbl...
> "Max" <zero@.maxdot.com.com> wrote in message
> news:ukaISv57EHA.2016@.TK2MSFTNGP15.phx.gbl...
>> Hi All!
>>
>> I'm doing an ASP.NET project which uses Persistent Forms Authentication
>> (i.e. once user logged in, they don't have to log in again). However
>> Session variables are erased after Session has timed out. So I need to
>> re-populate user specific session variables (such as user email, DOB,
>> Full Name...etc) when Session has ended.
>>
>> But strangely, when I tried to do something like...
>>
>> Dim strArrayUserInfo(10) as String
>>
>> strArrayUserInfo(0) = drDataReader("FName").ToString
>> strArrayUserInfo(1) = drDataReader("LName").ToString
>> strArrayUserInfo(2) = drDataReader("Email").ToString
>>
>> Session("UserInfoArray") = strArrayUserInfo
>>
>> I get System.StackOverflowException. If I comment out that line,
>> application runs correctly but fail at the point where
>> Session("UserInfoArray") is accessed (i.e. Null Exception). So I
>> de-comment the above code and I was thrown System.StackOverflowException
>> again.
>>
>> What could be the problem? I was merely assigning a variable to Session
>> variable collection. Why ASP.NET throws System.StackOverflowException??
> I bet you have something else called "Session". Change the line to refer
> to HttpContext.Current.Session and see if that's any better.
> John Saunders
"Max" <zero@.maxdot.com.com> wrote in message
news:edEOMA67EHA.2552@.TK2MSFTNGP09.phx.gbl...
> Hi John,
> Thanks for the quick response! Unfortunately, I get the same error :(
Several ideas, none brilliant.
1) Simplify, simplify, simplify
1a) Instead of filling from the datareader, try setting the array elements
to constants. It's simpler.
1b) Try using Session("a"). It's simpler.
2) Are you setting all 10 elements of the array?
3) Turn Options Strict On.
John Saunders
> "John Saunders" <johnwsaundersiii at hotmail.com> wrote in message
> news:ew5r0757EHA.2016@.TK2MSFTNGP15.phx.gbl...
>> "Max" <zero@.maxdot.com.com> wrote in message
>> news:ukaISv57EHA.2016@.TK2MSFTNGP15.phx.gbl...
>>> Hi All!
>>>
>>> I'm doing an ASP.NET project which uses Persistent Forms Authentication
>>> (i.e. once user logged in, they don't have to log in again). However
>>> Session variables are erased after Session has timed out. So I need to
>>> re-populate user specific session variables (such as user email, DOB,
>>> Full Name...etc) when Session has ended.
>>>
>>> But strangely, when I tried to do something like...
>>>
>>> Dim strArrayUserInfo(10) as String
>>>
>>> strArrayUserInfo(0) = drDataReader("FName").ToString
>>> strArrayUserInfo(1) = drDataReader("LName").ToString
>>> strArrayUserInfo(2) = drDataReader("Email").ToString
>>>
>>> Session("UserInfoArray") = strArrayUserInfo
>>>
>>> I get System.StackOverflowException. If I comment out that line,
>>> application runs correctly but fail at the point where
>>> Session("UserInfoArray") is accessed (i.e. Null Exception). So I
>>> de-comment the above code and I was thrown System.StackOverflowException
>>> again.
>>>
>>> What could be the problem? I was merely assigning a variable to
>>> Session variable collection. Why ASP.NET throws
>>> System.StackOverflowException??
>>
>> I bet you have something else called "Session". Change the line to refer
>> to HttpContext.Current.Session and see if that's any better.
>>
>> John Saunders
>>
>>
Hi John,
I tried reducing the Array length to 3 and still it didn't work. This is a
mystery and a nightmare.
Max
"John Saunders" <johnwsaundersiii at hotmail.com> wrote in message
news:uFWbK777EHA.2568@.TK2MSFTNGP10.phx.gbl...
> "Max" <zero@.maxdot.com.com> wrote in message
> news:edEOMA67EHA.2552@.TK2MSFTNGP09.phx.gbl...
>> Hi John,
>>
>> Thanks for the quick response! Unfortunately, I get the same error :(
> Several ideas, none brilliant.
> 1) Simplify, simplify, simplify
> 1a) Instead of filling from the datareader, try setting the array elements
> to constants. It's simpler.
> 1b) Try using Session("a"). It's simpler.
> 2) Are you setting all 10 elements of the array?
> 3) Turn Options Strict On.
> John Saunders
>
>> "John Saunders" <johnwsaundersiii at hotmail.com> wrote in message
>> news:ew5r0757EHA.2016@.TK2MSFTNGP15.phx.gbl...
>>> "Max" <zero@.maxdot.com.com> wrote in message
>>> news:ukaISv57EHA.2016@.TK2MSFTNGP15.phx.gbl...
>>>> Hi All!
>>>>
>>>> I'm doing an ASP.NET project which uses Persistent Forms Authentication
>>>> (i.e. once user logged in, they don't have to log in again). However
>>>> Session variables are erased after Session has timed out. So I need to
>>>> re-populate user specific session variables (such as user email, DOB,
>>>> Full Name...etc) when Session has ended.
>>>>
>>>> But strangely, when I tried to do something like...
>>>>
>>>> Dim strArrayUserInfo(10) as String
>>>>
>>>> strArrayUserInfo(0) = drDataReader("FName").ToString
>>>> strArrayUserInfo(1) = drDataReader("LName").ToString
>>>> strArrayUserInfo(2) = drDataReader("Email").ToString
>>>>
>>>> Session("UserInfoArray") = strArrayUserInfo
>>>>
>>>> I get System.StackOverflowException. If I comment out that line,
>>>> application runs correctly but fail at the point where
>>>> Session("UserInfoArray") is accessed (i.e. Null Exception). So I
>>>> de-comment the above code and I was thrown
>>>> System.StackOverflowException again.
>>>>
>>>> What could be the problem? I was merely assigning a variable to
>>>> Session variable collection. Why ASP.NET throws
>>>> System.StackOverflowException??
>>>
>>> I bet you have something else called "Session". Change the line to refer
>>> to HttpContext.Current.Session and see if that's any better.
>>>
>>> John Saunders
>>>
>>>
>>
>>
"Max" <zero@.maxdot.com.com> wrote in message
news:erNBq2U8EHA.2124@.TK2MSFTNGP14.phx.gbl...
> Hi John,
> I tried reducing the Array length to 3 and still it didn't work. This is a
> mystery and a nightmare.
Did you try using an array filled with constants? Did you try using
Session("a")? Have you turned Options Strict On?
John Saunders
> "John Saunders" <johnwsaundersiii at hotmail.com> wrote in message
> news:uFWbK777EHA.2568@.TK2MSFTNGP10.phx.gbl...
>> "Max" <zero@.maxdot.com.com> wrote in message
>> news:edEOMA67EHA.2552@.TK2MSFTNGP09.phx.gbl...
>>> Hi John,
>>>
>>> Thanks for the quick response! Unfortunately, I get the same error :(
>>
>> Several ideas, none brilliant.
>>
>> 1) Simplify, simplify, simplify
>> 1a) Instead of filling from the datareader, try setting the array
>> elements to constants. It's simpler.
>> 1b) Try using Session("a"). It's simpler.
>> 2) Are you setting all 10 elements of the array?
>> 3) Turn Options Strict On.
>>
>> John Saunders
>>
>>
>>
>>> "John Saunders" <johnwsaundersiii at hotmail.com> wrote in message
>>> news:ew5r0757EHA.2016@.TK2MSFTNGP15.phx.gbl...
>>>> "Max" <zero@.maxdot.com.com> wrote in message
>>>> news:ukaISv57EHA.2016@.TK2MSFTNGP15.phx.gbl...
>>>>> Hi All!
>>>>>
>>>>> I'm doing an ASP.NET project which uses Persistent Forms
>>>>> Authentication (i.e. once user logged in, they don't have to log in
>>>>> again). However Session variables are erased after Session has timed
>>>>> out. So I need to re-populate user specific session variables (such as
>>>>> user email, DOB, Full Name...etc) when Session has ended.
>>>>>
>>>>> But strangely, when I tried to do something like...
>>>>>
>>>>> Dim strArrayUserInfo(10) as String
>>>>>
>>>>> strArrayUserInfo(0) = drDataReader("FName").ToString
>>>>> strArrayUserInfo(1) = drDataReader("LName").ToString
>>>>> strArrayUserInfo(2) = drDataReader("Email").ToString
>>>>>
>>>>> Session("UserInfoArray") = strArrayUserInfo
>>>>>
>>>>> I get System.StackOverflowException. If I comment out that line,
>>>>> application runs correctly but fail at the point where
>>>>> Session("UserInfoArray") is accessed (i.e. Null Exception). So I
>>>>> de-comment the above code and I was thrown
>>>>> System.StackOverflowException again.
>>>>>
>>>>> What could be the problem? I was merely assigning a variable to
>>>>> Session variable collection. Why ASP.NET throws
>>>>> System.StackOverflowException??
>>>>
>>>> I bet you have something else called "Session". Change the line to
>>>> refer to HttpContext.Current.Session and see if that's any better.
>>>>
>>>> John Saunders
>>>>
>>>>
>>>
>>>
>>
>>
Persistent nonsecure content message when loading a file into an IFRAME element
I am having a problem with an IFRAME that is embedded into an ASPX
page (ASP.NET application). The IFRAME is originally empty (src='').
When a user selects a date from the drop-down list box above the
IFRAME, the IFRAME loads the content of a file on the local machine
(c:\bds\blahblahblah.txt).
The application that contains this page is running on a secure socket
layer (SSL). When the IFRAME tries to load the file, a message pops up
stating that "The page you are about to view contains both secure and
nonsecure content. Would you like to view the nonsecure content?".
I desperately need to get rid of this message. I have tried every
trick in the book, and so far, no dice. Here's what I have tried:
1. Setting security setting for Intranet to Low.
2. Adding the machine itself to its own list of trusted sites. Setting
trusted site security to Low.
3. Enabling everything in the security contents.
4. Enabling 'Display Mixed Contents'. Then disabling it. Then setting
it to Prompt. None of this made any difference.
5. Setting the src attribute of the IFRAME to blank (''). Setting it
to blank.html. Setting it to javascript:parent.nullSrc();, where
nullSrc() function in the parent page returns ''.
6. Setting application trust to full trust.
7. Installing every patch available. We are running IE 6 with SP1.
8. Sharing the folder containing the files I am trying to load. Web
sharing the same folder.
I can't think of other stuff, but I am sure I tried more than that. I
really hope you can help me with this, I am kinda running our of
creative ideas on resolving this problem.
Many thanks for your attention,
Helen.in IE under
Internetnet Options->Advanced->Security
uncheck "Warn if changing between secure and unsecure mode"
"Helen" <emailhelen@.comcast.net> wrote in message
news:516ce28b.0310151301.db4ff88@.posting.google.co m...
> Guys and gals,
> I am having a problem with an IFRAME that is embedded into an ASPX
> page (ASP.NET application). The IFRAME is originally empty (src='').
> When a user selects a date from the drop-down list box above the
> IFRAME, the IFRAME loads the content of a file on the local machine
> (c:\bds\blahblahblah.txt).
> The application that contains this page is running on a secure socket
> layer (SSL). When the IFRAME tries to load the file, a message pops up
> stating that "The page you are about to view contains both secure and
> nonsecure content. Would you like to view the nonsecure content?".
> I desperately need to get rid of this message. I have tried every
> trick in the book, and so far, no dice. Here's what I have tried:
> 1. Setting security setting for Intranet to Low.
> 2. Adding the machine itself to its own list of trusted sites. Setting
> trusted site security to Low.
> 3. Enabling everything in the security contents.
> 4. Enabling 'Display Mixed Contents'. Then disabling it. Then setting
> it to Prompt. None of this made any difference.
> 5. Setting the src attribute of the IFRAME to blank (''). Setting it
> to blank.html. Setting it to javascript:parent.nullSrc();, where
> nullSrc() function in the parent page returns ''.
> 6. Setting application trust to full trust.
> 7. Installing every patch available. We are running IE 6 with SP1.
> 8. Sharing the folder containing the files I am trying to load. Web
> sharing the same folder.
> I can't think of other stuff, but I am sure I tried more than that. I
> really hope you can help me with this, I am kinda running our of
> creative ideas on resolving this problem.
> Many thanks for your attention,
> Helen.
Bruce:
Thanks for your reply. I tried that, and it had no effect, before and
after I rebooted.
Helen.
Persistent information...
Am new to asp.net and I'm trying to find out how to keep persistent
information.
The main thing I need to do is carry round an encrypted connection string
for my database, but there are likelly to be other 'system' scoped data that
I'll need (database roles come to mind).
I've looked at the web.config file, but that only allows a static connection
string. I'm using forms authentication with a mixed mode SQL 2K server.
Cheers...PYou can use either Application variables, which exist for all users
for a web application, or Session variables, which exist for a
particular user session.
To use,
Application("MyApplicationVariable") = "Hello World"
or
Session("MySessionVariable")=123.45
"Paul M" <masonp@.trials.bham.ac.uk> wrote in message
news:ODrkbTNuDHA.2308@.TK2MSFTNGP09.phx.gbl...
> Hi folks,
> Am new to asp.net and I'm trying to find out how to keep persistent
> information.
> The main thing I need to do is carry round an encrypted connection
string
> for my database, but there are likelly to be other 'system' scoped
data that
> I'll need (database roles come to mind).
> I've looked at the web.config file, but that only allows a static
connection
> string. I'm using forms authentication with a mixed mode SQL 2K
server.
> Cheers...P
persistent variables?
I have tried using each "control" in a collection, which didnt work, anyways ...
I created a New Collection object, populated it and gave it so a Session() cookie to keep untill the next request/postback, but it only keps the first object in the collection?? :confused:
Does anyone know what I mean or should I write up a basic example showing what I mean?
Any help is appreciated, Thanks :)I think you should try explaining again. You mention persistence of variables, but you talk of controls...
Sure, I'll see if I can hack up a quick example tonight maybe (probably not enoguh time, I dont get home till late).
Maybe this will clarify in the mean time...
I am using a form full of controls, yes, but I am using a session cookie to keep information about these controls between postbacks, and because a single session cookie is keeping information for a fair couple controls it is holding a "collection"
So, a Session Variable is assigned a Collection containing information about the controls on the page.
The controls on your page, do they not persist their values between postbacks? That's the main idea behind ASP.NET.
The Frogs right.
Have you got viewstate enabled for each .net control ?
Persistent ViewState
Imagine a form with several TextBox WebControls and two buttons "New" which
should clear the form and "Save". On reloading or leaving the page which
holds the form the TextBoxes should be cleared so I've disabled the
ViewStates of these TextBoxes by setting the EnableViewState property to
false.
The method which is bound to the OnClick event of the "New" button is
empty. When clicked a PostBack occurs which, theoretically, should be
sufficient to clear the TextBoxes because their state shouldn't be saved.
Unfortunately after the PostBack the data is still there! I've had a look
into the HTML source and found out that the value property of the TextBoxes
is set, so there's still a ViewState?! Even a ViewState.Clear() and/or
ClearChildViewState() within OnClick() doesn't work!
Disabling the ViewState for the whole page is no solution because the page
also contains a DataGrid and other controls which depend on the ViewState.
Please help!
Sincerely
Sven JacobsViewState is a different state persistance mechanism than the normal <form>
post data. ViewState is for data that is not part of the normal POST. The
text in a Label is saved in ViewState because a <span> doesn't post when
the form is submitted. The text in a TExtBox will be submitted, and thus
disabling viewstate has no effect on that.
-Brock
DevelopMentor
http://staff.develop.com/ballen
> Hello everybody!
> Imagine a form with several TextBox WebControls and two buttons "New"
> which should clear the form and "Save". On reloading or leaving the
> page which holds the form the TextBoxes should be cleared so I've
> disabled the ViewStates of these TextBoxes by setting the
> EnableViewState property to false.
> The method which is bound to the OnClick event of the "New" button is
> empty. When clicked a PostBack occurs which, theoretically, should be
> sufficient to clear the TextBoxes because their state shouldn't be
> saved. Unfortunately after the PostBack the data is still there! I've
> had a look into the HTML source and found out that the value property
> of the TextBoxes is set, so there's still a ViewState?! Even a
> ViewState.Clear() and/or ClearChildViewState() within OnClick()
> doesn't work!
> Disabling the ViewState for the whole page is no solution because the
> page also contains a DataGrid and other controls which depend on the
> ViewState.
> Please help!
>
> ViewState is a different state persistance mechanism than the normal <form>
> post data. ViewState is for data that is not part of the normal POST. The
> text in a Label is saved in ViewState because a <span> doesn't post when
> the form is submitted. The text in a TExtBox will be submitted, and thus
> disabling viewstate has no effect on that.
So what you saying is that the state persistance of a form is a feature of
HTTP / the browser? How to clear the form then, via JavaScript?
Thanks!
Sincerely
Sven Jacobs
> So what you saying is that the state persistance of a form is a feature of
> HTTP / the browser? How to clear the form then, via JavaScript?
Forget that! After reading this article
http://aspalliance.com/articleViewer.aspx?aId=135 I think I now what the
difference between ViewState and PostBack data is.
So what I have to do is not to import the PostBack data on a special
condition (=New button clicked).
Sincerely
Sven Jacobs
No, the form persistance is a feature of the ASP.NET runtime, in that it
matches the control id in the POST data and fills the associated value from
that. See
http://msdn.microsoft.com/library/d...br />
tate.asp
To clear the form, loop through the controls on the form, and check if the
control is a textbox, or certain type of control, then set the value to an
empty string, or index to -1 if a droplist etc. It really depends on what
type of control you are working with as there is no generic way of clearing
a form (AFAIK).
- Paul Glavich
ASP.NET MVP
ASPInsider (www.aspinsiders.com)
"Sven Jacobs" <sven.jacobs@.web.de> wrote in message
news:178f7ojd7o9bi.719p7zwjzasv$.dlg@.40tude.net...
<form>
The
> So what you saying is that the state persistance of a form is a feature of
> HTTP / the browser? How to clear the form then, via JavaScript?
> Thanks!
> --
> Sincerely
> Sven Jacobs
Persistent ViewState
Imagine a form with several TextBox WebControls and two buttons "New" which
should clear the form and "Save". On reloading or leaving the page which
holds the form the TextBoxes should be cleared so I've disabled the
ViewStates of these TextBoxes by setting the EnableViewState property to
false.
The method which is bound to the OnClick event of the "New" button is
empty. When clicked a PostBack occurs which, theoretically, should be
sufficient to clear the TextBoxes because their state shouldn't be saved.
Unfortunately after the PostBack the data is still there! I've had a look
into the HTML source and found out that the value property of the TextBoxes
is set, so there's still a ViewState?! Even a ViewState.Clear() and/or
ClearChildViewState() within OnClick() doesn't work!
Disabling the ViewState for the whole page is no solution because the page
also contains a DataGrid and other controls which depend on the ViewState.
Please help!
--
Sincerely
Sven JacobsViewState is a different state persistance mechanism than the normal <form>
post data. ViewState is for data that is not part of the normal POST. The
text in a Label is saved in ViewState because a <span> doesn't post when
the form is submitted. The text in a TExtBox will be submitted, and thus
disabling viewstate has no effect on that.
-Brock
DevelopMentor
http://staff.develop.com/ballen
> Hello everybody!
> Imagine a form with several TextBox WebControls and two buttons "New"
> which should clear the form and "Save". On reloading or leaving the
> page which holds the form the TextBoxes should be cleared so I've
> disabled the ViewStates of these TextBoxes by setting the
> EnableViewState property to false.
> The method which is bound to the OnClick event of the "New" button is
> empty. When clicked a PostBack occurs which, theoretically, should be
> sufficient to clear the TextBoxes because their state shouldn't be
> saved. Unfortunately after the PostBack the data is still there! I've
> had a look into the HTML source and found out that the value property
> of the TextBoxes is set, so there's still a ViewState?! Even a
> ViewState.Clear() and/or ClearChildViewState() within OnClick()
> doesn't work!
> Disabling the ViewState for the whole page is no solution because the
> page also contains a DataGrid and other controls which depend on the
> ViewState.
> Please help!
> ViewState is a different state persistance mechanism than the normal <form>
> post data. ViewState is for data that is not part of the normal POST. The
> text in a Label is saved in ViewState because a <span> doesn't post when
> the form is submitted. The text in a TExtBox will be submitted, and thus
> disabling viewstate has no effect on that.
So what you saying is that the state persistance of a form is a feature of
HTTP / the browser? How to clear the form then, via JavaScript?
Thanks!
--
Sincerely
Sven Jacobs
> So what you saying is that the state persistance of a form is a feature of
> HTTP / the browser? How to clear the form then, via JavaScript?
Forget that! After reading this article
http://aspalliance.com/articleViewer.aspx?aId=135 I think I now what the
difference between ViewState and PostBack data is.
So what I have to do is not to import the PostBack data on a special
condition (=New button clicked).
--
Sincerely
Sven Jacobs
No, the form persistance is a feature of the ASP.NET runtime, in that it
matches the control id in the POST data and fills the associated value from
that. See
http://msdn.microsoft.com/library/d...l/viewstate.asp
To clear the form, loop through the controls on the form, and check if the
control is a textbox, or certain type of control, then set the value to an
empty string, or index to -1 if a droplist etc. It really depends on what
type of control you are working with as there is no generic way of clearing
a form (AFAIK).
--
- Paul Glavich
ASP.NET MVP
ASPInsider (www.aspinsiders.com)
"Sven Jacobs" <sven.jacobs@.web.de> wrote in message
news:178f7ojd7o9bi.719p7zwjzasv$.dlg@.40tude.net...
> > ViewState is a different state persistance mechanism than the normal
<form>
> > post data. ViewState is for data that is not part of the normal POST.
The
> > text in a Label is saved in ViewState because a <span> doesn't post when
> > the form is submitted. The text in a TExtBox will be submitted, and thus
> > disabling viewstate has no effect on that.
> So what you saying is that the state persistance of a form is a feature of
> HTTP / the browser? How to clear the form then, via JavaScript?
> Thanks!
> --
> Sincerely
> Sven Jacobs