Showing posts with label run. Show all posts
Showing posts with label run. Show all posts

Thursday, March 29, 2012

Performance problems using ASP.NET 2.0

I have just built my first ASP.NET v2.0 app and have it running on a 3 server web farm that runs several other ASP.NET v1.1 apps. The v1.1 apps run great, but the new v2.0 app always seems to run very slowly when first connecting to the site, even if other users have already visited the site. I believe I have pre-compiled the site, and even if I visit each server in turn to ensure the app has been compiled before hitting the load-balanced url, the site just runs very slowly. On our development machines the site runs very quickly, so the poor performance is a bit of a mystery.

The servers in the farm are running Windows 2003 Server and the machine.config on each server has been updated to syncronize the machine keys.

Check the event viewer to see if the app pool is restarting itself. Some people had problems with the application shutting down and if that's your case then when the app (aspnet) restarts itself the code has to recompile. Any other details that you might find, will help on directing you towards the right path.

hi

are u working with directory. The asp.net 2.0 application restart as soon as the directory structure changes. see the post below

http://vikramlakhotia.com/Post.aspx?postID=6

Hope this helps

Vikram

Vikram's Blog


Did not know that. If that's the case that's a huge bug on asp.net 2.0. It should be reported. Maybe there's a setting on the Machine.Config for the application not to restart when the directory structure changes.
There was nothing in the event viewer for all three servers (relating to asp.net anyway). The slow responses almost feel like every page request is causing the application to be re-built...

I don't know what else to tell you. Maybe you have indexing on and it's getting ahold of the files and thus restarting. Just throwing one out there.

Try creating another app and see how it behaves. If it behaves normal, then the problem is related to your application.

Monday, March 26, 2012

periodic emailing?

Can anyone recommend a good way to email in ASP.net. I need some suggestions on how to kick off a task that can run every day and send emails.

Thanks!

Chirag

you really shouldn't make a web application for that...

make a windows application en schedule it on windows...

quick search on the web:

http://www.codeproject.com/vb/net/epsendmail.asp


You can also create a service and configure it to run on automatically on start up. It all depends on your needs and security access you have to the box.

Thanks guys, but it needs to be part of an ASP.net web site. I want to add it to the following starter kit:

http://msdn.microsoft.com/asp.net/default.aspx?pull=/library/en-us/dnaspp/html/clubwebsitesk.asp

Any ideas?

Saturday, March 24, 2012

permission denied on object sp_sdidebug

Hi, whenever I attach the asp_net to a web site, checking 3 boxes aspnet,
t-SQL and scripting in the dialog box, run the web site, I get te following
error in spite of the fact I am logged as an administrator and the tyhe
connectionn string has trusted conn.:
SqlException: EXECUTE permission denied on object 'sp_sdidebug', database
'master', owner 'dbo'.]
System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior
cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
System.Data.SqlClient.SqlCommand.ExecuteNonQuery() +195
Thanks for your helpHi,
are you using Windows authentication or SQL Server authentication for
conecting to the DB. Or may be grant execute rights to the user through whic
h
you are loggin into in SQL Server.
HTH.
Kaustav Neogy.
"SalamElias" wrote:

> Hi, whenever I attach the asp_net to a web site, checking 3 boxes aspnet,
> t-SQL and scripting in the dialog box, run the web site, I get te followin
g
> error in spite of the fact I am logged as an administrator and the tyhe
> connectionn string has trusted conn.:
> SqlException: EXECUTE permission denied on object 'sp_sdidebug', database
> 'master', owner 'dbo'.]
> System.Data.SqlClient.SqlCommand.ExecuteReader(CommandBehavior
> cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
> System.Data.SqlClient.SqlCommand.ExecuteNonQuery() +195
> Thanks for your help
Hi SalamElias,
I think Kaustav's suggestion on checking the SQL db's security setting is
resonable. From the error info you provided, your program failed when try
to call a store procedure in the sql db. As Kaustav has said, you should
grant the proper permissions to the account you used to connect the sql db.
IF using Sqlserver authentication, that's the account you specify in the
connectionstring, if windows authentication, that'll be your asp.net
applications process identity if you 're not using impersonate.
Please feel free to let me know if you have anything unclear or there is
anything else we haven't quite understand well. Thanks.
Regards,
Steven Cheng
Microsoft Online Support
Get Secure! www.microsoft.com/security
(This posting is provided "AS IS", with no warranties, and confers no
rights.)

permission denied on object sp_sdidebug

Hi, whenever I attach the asp_net to a web site, checking 3 boxes aspnet,
t-SQL and scripting in the dialog box, run the web site, I get te following
error in spite of the fact I am logged as an administrator and the tyhe
connectionn string has trusted conn.:
SqlException: EXECUTE permission denied on object 'sp_sdidebug', database
'master', owner 'dbo'.]
System.Data.SqlClient.SqlCommand.ExecuteReader(Com mandBehavior
cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
System.Data.SqlClient.SqlCommand.ExecuteNonQuery() +195

Thanks for your helpHi,

are you using Windows authentication or SQL Server authentication for
conecting to the DB. Or may be grant execute rights to the user through which
you are loggin into in SQL Server.

HTH.

Kaustav Neogy.

"SalamElias" wrote:

> Hi, whenever I attach the asp_net to a web site, checking 3 boxes aspnet,
> t-SQL and scripting in the dialog box, run the web site, I get te following
> error in spite of the fact I am logged as an administrator and the tyhe
> connectionn string has trusted conn.:
> SqlException: EXECUTE permission denied on object 'sp_sdidebug', database
> 'master', owner 'dbo'.]
> System.Data.SqlClient.SqlCommand.ExecuteReader(Com mandBehavior
> cmdBehavior, RunBehavior runBehavior, Boolean returnStream) +742
> System.Data.SqlClient.SqlCommand.ExecuteNonQuery() +195
> Thanks for your help
Hi SalamElias,

I think Kaustav's suggestion on checking the SQL db's security setting is
resonable. From the error info you provided, your program failed when try
to call a store procedure in the sql db. As Kaustav has said, you should
grant the proper permissions to the account you used to connect the sql db.
IF using Sqlserver authentication, that's the account you specify in the
connectionstring, if windows authentication, that'll be your asp.net
applications process identity if you 're not using impersonate.
Please feel free to let me know if you have anything unclear or there is
anything else we haven't quite understand well. Thanks.

Regards,

Steven Cheng
Microsoft Online Support

Get Secure! www.microsoft.com/security
(This posting is provided "AS IS", with no warranties, and confers no
rights.)

Permission required to execute a DTS package from ASP.NET app

Hello,

I'm calling a DTS package from my asp.net application.Apparently because of
permission issue I canot run the package within the sql server ,because when
I set it to call a package from my local host it can execute te package.one
step before calling the package I get the IDENTITY of the current security
context and it is my Domian user name and I'm using IntegratedSecurity to
call the DTS package.I'm also memeber of sysadmin rols in Database.Do I have
to give it extra permissions?

Thasnk"Ray5531" <Ray5531@.microsoft.com> wrote in
news:#QTNS10hFHA.3164@.TK2MSFTNGP15.phx.gbl:

> Hello,
> I'm calling a DTS package from my asp.net application.Apparently
> because of permission issue I canot run the package within the sql
> server ,because when I set it to call a package from my local host it
> can execute te package.one step before calling the package I get the
> IDENTITY of the current security context and it is my Domian user name
> and I'm using IntegratedSecurity to call the DTS package.I'm also
> memeber of sysadmin rols in Database.Do I have to give it extra
> permissions?
> Thasnk

Hi Ray,

If you are using SSPI in the connectionstring, you have to impersonate the
call to the DTS.
You can do that by adding the next line to the web.config:
<identity impersonate="true" /
link: http://msdn.microsoft.com/library/d...rl=/library/en-
us/vsent7/html/vxconImpersonation.asp

Pablo
> If you are using SSPI in the connectionstring, you have to impersonate the
> call to the DTS.
> You can do that by adding the next line to the web.config:
> <identity impersonate="true" /
I've done this ,that's why the curent security context is under my
identity:)

Thanks
"Pablo Galiano" <pagaliano@.hotmail.com> wrote in message
news:Xns969288D8242Apagalianohotmailcom@.207.46.248 .16...
> "Ray5531" <Ray5531@.microsoft.com> wrote in
> news:#QTNS10hFHA.3164@.TK2MSFTNGP15.phx.gbl:
>> Hello,
>>
>> I'm calling a DTS package from my asp.net application.Apparently
>> because of permission issue I canot run the package within the sql
>> server ,because when I set it to call a package from my local host it
>> can execute te package.one step before calling the package I get the
>> IDENTITY of the current security context and it is my Domian user name
>> and I'm using IntegratedSecurity to call the DTS package.I'm also
>> memeber of sysadmin rols in Database.Do I have to give it extra
>> permissions?
>>
>> Thasnk
>>
>>
>>
> Hi Ray,
> If you are using SSPI in the connectionstring, you have to impersonate the
> call to the DTS.
> You can do that by adding the next line to the web.config:
> <identity impersonate="true" />
> link: http://msdn.microsoft.com/library/d...rl=/library/en-
> us/vsent7/html/vxconImpersonation.asp
>
> Pablo

permissions

I just moved my old server to a new and in the process upgraded from win2k to win2k3. The problem is whenever users try to run a page that processes a file (creates a thumbnail) the permission is denied.

I have given

ASP.NET MACHINE ACCOUNT and
INTERNET GUEST ACCOUNT

MODIFY
READ AND EXECUTE
LIST FOLDER CONTENTS
READ
WRITE

However, still no luck. Is this a security risk giving these permissions to these accounts? And what do I have to do to get it working!?. Is this because security on win2k3 is tighter? I swear it worked like a charm on win2k

Any help greatly appreciated.

Thanks

Mike123

(Error Below)

Exception Details: System.UnauthorizedAccessException: Access to the path "e:\web\pics\uploads\bob07.jpg" is denied.

ASP.NET is not authorized to access the requested resource. Consider granting access rights to the resource to the ASP.NET request identity. ASP.NET has a base process identity (typically {MACHINE}\ASPNET on IIS 5 or Network Service on IIS 6) that is used if the application is not impersonating. If the application is impersonating via <identity impersonate="true"/>, the identity will be the anonymous user (typically IUSR_MACHINENAME) or the authenticated request user.

To grant ASP.NET write access to a file, right-click the file in Explorer, choose "Properties" and select the Security tab. Click "Add" to add the appropriate user or group. Highlight the ASP.NET account, and check the boxes for the desired accessso you've made the changes to permisions where? IIS console? You'll also need to alter the NTFS ACLs trhough windows explorer's 'security' pane (under the properties window)
I did that as well , but no luck =[

am i setting the wrong accounts??
Any luck since Mike?

Matt.
Yes I got it.

I believe it was the NT Services account that did not have permission that needed it.
Are you talking about the Windows NT Services, as in the modules which perform functions for Windows NT, or an actual account which I don't appear to have on my system? Where would I look for this?

More importantly, what did you do exactly to get it working?

Thanks muchly,
Matt.
Dont quote me on this but as I remember it an actual account. 2k3 is setup a bit differently. All I did was give this account permissions and it worked.

Wednesday, March 21, 2012

Permissions needed to run aspnet_regiis.exe -c

Hi,
I'm trying to install the client side scripts on a server, but I always get
the following error:
An error has occurred (0x80070005).
You must have administrative rights on this machine in order to run this
tool.
I am logged on as a domain admin on the server. Anyone know the specific
permissions needed to run the tool?
Thanks
Ericadmin on the box, not admin of the domain,
"Eric Caron" <ecaron@.nospam.quebecaffaires.com> wrote in message
news:e6H#X8wGEHA.712@.tk2msftngp13.phx.gbl...
> Hi,
> I'm trying to install the client side scripts on a server, but I always
get
> the following error:
> An error has occurred (0x80070005).
> You must have administrative rights on this machine in order to run this
> tool.
> I am logged on as a domain admin on the server. Anyone know the specific
> permissions needed to run the tool?
> Thanks
> Eric
>
Well, obviously I am. When you join a server to a domain, the Domain Admin
group is automatically added to the local Administrators group. I verified
it to be sure that nothing had changed. I think it's really a permissions
problem somewhere.
"Mike" <scoobyDoo@.sbcglobal.net> wrote in message
news:upsvkjyGEHA.3372@.TK2MSFTNGP09.phx.gbl...
> admin on the box, not admin of the domain,
>
> "Eric Caron" <ecaron@.nospam.quebecaffaires.com> wrote in message
> news:e6H#X8wGEHA.712@.tk2msftngp13.phx.gbl...
> get
specific
>
Obviously your not you could run it now.
Check again, just because your an admin on the domain does not make you a
admin on the local machine
I'm currently an admin on my local pc but not the domain.
"Eric Caron" <ecaron@.nospam.quebecaffaires.com> wrote in message
news:u8WqsvyGEHA.628@.TK2MSFTNGP10.phx.gbl...
> Well, obviously I am. When you join a server to a domain, the Domain
Admin
> group is automatically added to the local Administrators group. I
verified
> it to be sure that nothing had changed. I think it's really a permissions
> problem somewhere.
> "Mike" <scoobyDoo@.sbcglobal.net> wrote in message
> news:upsvkjyGEHA.3372@.TK2MSFTNGP09.phx.gbl...
always
this
> specific
>

Permissions needed to run aspnet_regiis.exe -c

Hi,

I'm trying to install the client side scripts on a server, but I always get
the following error:

An error has occurred (0x80070005).
You must have administrative rights on this machine in order to run this
tool.

I am logged on as a domain admin on the server. Anyone know the specific
permissions needed to run the tool?

Thanks

Ericadmin on the box, not admin of the domain,

"Eric Caron" <ecaron@.nospam.quebecaffaires.com> wrote in message
news:e6H#X8wGEHA.712@.tk2msftngp13.phx.gbl...
> Hi,
> I'm trying to install the client side scripts on a server, but I always
get
> the following error:
> An error has occurred (0x80070005).
> You must have administrative rights on this machine in order to run this
> tool.
> I am logged on as a domain admin on the server. Anyone know the specific
> permissions needed to run the tool?
> Thanks
> Eric
Well, obviously I am. When you join a server to a domain, the Domain Admin
group is automatically added to the local Administrators group. I verified
it to be sure that nothing had changed. I think it's really a permissions
problem somewhere.

"Mike" <scoobyDoo@.sbcglobal.net> wrote in message
news:upsvkjyGEHA.3372@.TK2MSFTNGP09.phx.gbl...
> admin on the box, not admin of the domain,
>
> "Eric Caron" <ecaron@.nospam.quebecaffaires.com> wrote in message
> news:e6H#X8wGEHA.712@.tk2msftngp13.phx.gbl...
> > Hi,
> > I'm trying to install the client side scripts on a server, but I always
> get
> > the following error:
> > An error has occurred (0x80070005).
> > You must have administrative rights on this machine in order to run this
> > tool.
> > I am logged on as a domain admin on the server. Anyone know the
specific
> > permissions needed to run the tool?
> > Thanks
> > Eric
Obviously your not you could run it now.
Check again, just because your an admin on the domain does not make you a
admin on the local machine
I'm currently an admin on my local pc but not the domain.

"Eric Caron" <ecaron@.nospam.quebecaffaires.com> wrote in message
news:u8WqsvyGEHA.628@.TK2MSFTNGP10.phx.gbl...
> Well, obviously I am. When you join a server to a domain, the Domain
Admin
> group is automatically added to the local Administrators group. I
verified
> it to be sure that nothing had changed. I think it's really a permissions
> problem somewhere.
> "Mike" <scoobyDoo@.sbcglobal.net> wrote in message
> news:upsvkjyGEHA.3372@.TK2MSFTNGP09.phx.gbl...
> > admin on the box, not admin of the domain,
> > "Eric Caron" <ecaron@.nospam.quebecaffaires.com> wrote in message
> > news:e6H#X8wGEHA.712@.tk2msftngp13.phx.gbl...
> > > Hi,
> > > > I'm trying to install the client side scripts on a server, but I
always
> > get
> > > the following error:
> > > > An error has occurred (0x80070005).
> > > You must have administrative rights on this machine in order to run
this
> > > tool.
> > > > I am logged on as a domain admin on the server. Anyone know the
> specific
> > > permissions needed to run the tool?
> > > > Thanks
> > > > Eric
> >

Permissions needed to run aspnet_regiis.exe -c

Hi,

I'm trying to install the client side scripts on a server, but I always get
the following error:

An error has occurred (0x80070005).
You must have administrative rights on this machine in order to run this
tool.

I am logged on as a domain admin on the server. Anyone know the specific
permissions needed to run the tool?

Thanks

Ericadmin on the box, not admin of the domain,

"Eric Caron" <ecaron@.nospam.quebecaffaires.com> wrote in message
news:e6H#X8wGEHA.712@.tk2msftngp13.phx.gbl...
> Hi,
> I'm trying to install the client side scripts on a server, but I always
get
> the following error:
> An error has occurred (0x80070005).
> You must have administrative rights on this machine in order to run this
> tool.
> I am logged on as a domain admin on the server. Anyone know the specific
> permissions needed to run the tool?
> Thanks
> Eric
Well, obviously I am. When you join a server to a domain, the Domain Admin
group is automatically added to the local Administrators group. I verified
it to be sure that nothing had changed. I think it's really a permissions
problem somewhere.

"Mike" <scoobyDoo@.sbcglobal.net> wrote in message
news:upsvkjyGEHA.3372@.TK2MSFTNGP09.phx.gbl...
> admin on the box, not admin of the domain,
>
> "Eric Caron" <ecaron@.nospam.quebecaffaires.com> wrote in message
> news:e6H#X8wGEHA.712@.tk2msftngp13.phx.gbl...
> > Hi,
> > I'm trying to install the client side scripts on a server, but I always
> get
> > the following error:
> > An error has occurred (0x80070005).
> > You must have administrative rights on this machine in order to run this
> > tool.
> > I am logged on as a domain admin on the server. Anyone know the
specific
> > permissions needed to run the tool?
> > Thanks
> > Eric
Obviously your not you could run it now.
Check again, just because your an admin on the domain does not make you a
admin on the local machine
I'm currently an admin on my local pc but not the domain.

"Eric Caron" <ecaron@.nospam.quebecaffaires.com> wrote in message
news:u8WqsvyGEHA.628@.TK2MSFTNGP10.phx.gbl...
> Well, obviously I am. When you join a server to a domain, the Domain
Admin
> group is automatically added to the local Administrators group. I
verified
> it to be sure that nothing had changed. I think it's really a permissions
> problem somewhere.
> "Mike" <scoobyDoo@.sbcglobal.net> wrote in message
> news:upsvkjyGEHA.3372@.TK2MSFTNGP09.phx.gbl...
> > admin on the box, not admin of the domain,
> > "Eric Caron" <ecaron@.nospam.quebecaffaires.com> wrote in message
> > news:e6H#X8wGEHA.712@.tk2msftngp13.phx.gbl...
> > > Hi,
> > > > I'm trying to install the client side scripts on a server, but I
always
> > get
> > > the following error:
> > > > An error has occurred (0x80070005).
> > > You must have administrative rights on this machine in order to run
this
> > > tool.
> > > > I am logged on as a domain admin on the server. Anyone know the
> specific
> > > permissions needed to run the tool?
> > > > Thanks
> > > > Eric
> >

Permissions Problem?

Hello All,
I can't seem to get my project to run in debug mode. When I run the web
application it says, "Error while trying to run project: Unable to start
debugging on the web server."
Any ideas?
LandersHi:
To resolve this problem, you must restart IIS. To do this, type iisreset at
a command prompt. - MS Knowledge Base.
Hope this helps.
Thanks,
Hrishi
"Landley" wrote:

> Hello All,
> I can't seem to get my project to run in debug mode. When I run the web
> application it says, "Error while trying to run project: Unable to start
> debugging on the web server."
> Any ideas?
> Landers
>
>
Hope this helps!
http://support.microsoft.com/defaul...kb;en-us;306172
Hrishi
"Landley" wrote:

> Hello All,
> I can't seem to get my project to run in debug mode. When I run the web
> application it says, "Error while trying to run project: Unable to start
> debugging on the web server."
> Any ideas?
> Landers
>
>
Thanks for your reply.
I have already tried the iis restart, and have already reinstalled ASP and
checked that the server components were installed also. Still no joy.
Any other ideas?
Landers
"Hrishi R" <HrishiR@.discussions.microsoft.com> wrote in message
news:E7BD5245-629D-4790-B8FA-325B951DA60D@.microsoft.com...
> Hope this helps!
> http://support.microsoft.com/defaul...kb;en-us;306172
> Hrishi
> "Landley" wrote:
>
This issue seems to be when I am running the IDE on the local machine (the
web server), as I have just connected and debugged remotely.
Any ideas why this is?
Landers.
"Landley" <news@.creations-software.co.uk> wrote in message
news:Oy%23u1OJzEHA.2692@.TK2MSFTNGP10.phx.gbl...
> Thanks for your reply.
> I have already tried the iis restart, and have already reinstalled ASP and
> checked that the server components were installed also. Still no joy.
> Any other ideas?
> Landers
> "Hrishi R" <HrishiR@.discussions.microsoft.com> wrote in message
> news:E7BD5245-629D-4790-B8FA-325B951DA60D@.microsoft.com...
web
start
>
Hello All,
I am having the same problem as Landers, any solutions ?
Angie
From http://www.developmentnow.com/g/8_2...elopmentnow.com
Hi, Angie.
Have you tried the solutions offered at :
http://support.microsoft.com/defaul...kb;en-us;306172
?
Juan T. Llibre
ASP.NET MVP
http://asp.net.do/foros/
Foros de ASP.NET en Espaol
Ven, y hablemos de ASP.NET...
======================
"Angie" <miewtee.ng@.citigroup.com> wrote in message
news:7939e9e7-b3f1-4fe5-ace2-ef403aa5c5e2@.msnews.microsoft.com...
> Hello All,
> I am having the same problem as Landers, any solutions ?
> Angie
> From http://www.developmentnow.com/g/8_2...ons-Problem.htm[/c
olor]

Permissions Problem?

Hello All,

I can't seem to get my project to run in debug mode. When I run the web
application it says, "Error while trying to run project: Unable to start
debugging on the web server."

Any ideas?

LandersHi:

To resolve this problem, you must restart IIS. To do this, type iisreset at
a command prompt. - MS Knowledge Base.

Hope this helps.

Thanks,
Hrishi

"Landley" wrote:

> Hello All,
> I can't seem to get my project to run in debug mode. When I run the web
> application it says, "Error while trying to run project: Unable to start
> debugging on the web server."
> Any ideas?
> Landers
>
Hope this helps!
http://support.microsoft.com/defaul...kb;en-us;306172

Hrishi

"Landley" wrote:

> Hello All,
> I can't seem to get my project to run in debug mode. When I run the web
> application it says, "Error while trying to run project: Unable to start
> debugging on the web server."
> Any ideas?
> Landers
>
Thanks for your reply.

I have already tried the iis restart, and have already reinstalled ASP and
checked that the server components were installed also. Still no joy.

Any other ideas?

Landers
"Hrishi R" <HrishiR@.discussions.microsoft.com> wrote in message
news:E7BD5245-629D-4790-B8FA-325B951DA60D@.microsoft.com...
> Hope this helps!
> http://support.microsoft.com/defaul...kb;en-us;306172
> Hrishi
> "Landley" wrote:
> > Hello All,
> > I can't seem to get my project to run in debug mode. When I run the web
> > application it says, "Error while trying to run project: Unable to start
> > debugging on the web server."
> > Any ideas?
> > Landers
This issue seems to be when I am running the IDE on the local machine (the
web server), as I have just connected and debugged remotely.

Any ideas why this is?

Landers.

"Landley" <news@.creations-software.co.uk> wrote in message
news:Oy%23u1OJzEHA.2692@.TK2MSFTNGP10.phx.gbl...
> Thanks for your reply.
> I have already tried the iis restart, and have already reinstalled ASP and
> checked that the server components were installed also. Still no joy.
> Any other ideas?
> Landers
> "Hrishi R" <HrishiR@.discussions.microsoft.com> wrote in message
> news:E7BD5245-629D-4790-B8FA-325B951DA60D@.microsoft.com...
> > Hope this helps!
> > http://support.microsoft.com/defaul...kb;en-us;306172
> > Hrishi
> > "Landley" wrote:
> > > Hello All,
> > > > I can't seem to get my project to run in debug mode. When I run the
web
> > > application it says, "Error while trying to run project: Unable to
start
> > > debugging on the web server."
> > > > Any ideas?
> > > > Landers
> > >
Hello All,

I am having the same problem as Landers, any solutions ?

Angi

From http://www.developmentnow.com/g/8_2...ions-Problem.ht

Posted via DevelopmentNow.com Group
http://www.developmentnow.com
Hi, Angie.

Have you tried the solutions offered at :
http://support.microsoft.com/defaul...kb;en-us;306172

?

Juan T. Llibre
ASP.NET MVP
http://asp.net.do/foros/
Foros de ASP.NET en Espaol
Ven, y hablemos de ASP.NET...
======================

"Angie" <miewtee.ng@.citigroup.com> wrote in message
news:7939e9e7-b3f1-4fe5-ace2-ef403aa5c5e2@.msnews.microsoft.com...
> Hello All,
> I am having the same problem as Landers, any solutions ?
> Angie
> From http://www.developmentnow.com/g/8_2...ons-Problem.htm

Friday, March 16, 2012

Persist Variable values

I've run into what seems to be an issue with persisting state. I'm new
to ASP.NET but have been using C# for a while now. I'm coding a
button_click method in the .cs file for a web page and trying to track
the number of times the button has been clicked.
The issue is, everytime the button is clicked, the page seems to
reload and I'm losing the variable value that I'm using to keep track
of the number of times the button is clicked. i couldn't find a
propert setting
I'm guessing the easiest way would be to add the code into a script
section of the client side code, but what about using a browser other
than IE? Would the data still get refreshed when the button is
clicked? I get the feeling these are some of the fundemental questions
in web apps.
Thanks for any suggestions.Do you want to track it specific to each user's session or the number of
times it is clicked 'application' -wide?
This has two very different implications. If you want to track per session,
in order to persist the value postback-to-postback, you can record it in the
Session object, a database using the caller's session key, xml file, etc...
and refresh (re-read) it each postback. You could perform this write
operation in the button's OnClick event.
If you want to track it for the application as a whole, you can store it in
the Application object but be aware that this will reset whenever the
application is restarted if you don't write it to persistent storage.
Some other options include cookies, writing the value to the ViewState or
hidden form fields but I'm an advocate of the other approach as it doesn't
depend on the user to keep cookies alive or store what you consider to be
important on the user's browser.
"Looch" wrote:

> I've run into what seems to be an issue with persisting state. I'm new
> to ASP.NET but have been using C# for a while now. I'm coding a
> button_click method in the .cs file for a web page and trying to track
> the number of times the button has been clicked.
> The issue is, everytime the button is clicked, the page seems to
> reload and I'm losing the variable value that I'm using to keep track
> of the number of times the button is clicked. i couldn't find a
> propert setting
> I'm guessing the easiest way would be to add the code into a script
> section of the client side code, but what about using a browser other
> than IE? Would the data still get refreshed when the button is
> clicked? I get the feeling these are some of the fundemental questions
> in web apps.
> Thanks for any suggestions.
>
Thanks for the explanation, that definitely clears it up for me!
Thanks again.

persistant cookie, what is it?

I have searched but info is limitted.
In my test app i used a non persistant cookie for forms authentication.
slidingExpiration is set to true
On run and close and rerun the login remains ok.
I have a time-out of one minute and indeed, it directs me to the login if i
wait to long.
The slidingExpiration does it's work also.
So were is this persistance for?
Thanks,What do you mean by "close" ? A non persistant cookie shouldn't survive when
the browser is closed and launched again (unlike a persistant cookie)...
Patrice
"Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl...
> I have searched but info is limitted.
> In my test app i used a non persistant cookie for forms authentication.
> slidingExpiration is set to true
> On run and close and rerun the login remains ok.
> I have a time-out of one minute and indeed, it directs me to the login if
i
> wait to long.
> The slidingExpiration does it's work also.
> So were is this persistance for?
> Thanks,
>
>
Well it does..
And indeed i mean run, close the browser, and run again.
But then this was all tested in the VWD environment.
What you are telling me is what i expected.
In our case we might choose for non-persistance.
"Patrice" <a@.bc.c> schreef in bericht
news:OC1VTrYJGHA.1728@.TK2MSFTNGP14.phx.gbl...
> What do you mean by "close" ? A non persistant cookie shouldn't survive
> when
> the browser is closed and launched again (unlike a persistant cookie)...
> --
> Patrice
> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
> news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl...
> i
>
tested again, indeed, even while i have persistance set to false, on browser
restart it never passes the login page.
"Edwin Knoppert" <news@.hellobasic.com> schreef in bericht
news:43ddf3fb$0$12849$ba620dc5@.text.nova.planet.nl...
> Well it does..
> And indeed i mean run, close the browser, and run again.
> But then this was all tested in the VWD environment.
> What you are telling me is what i expected.
> In our case we might choose for non-persistance.
>
> "Patrice" <a@.bc.c> schreef in bericht
> news:OC1VTrYJGHA.1728@.TK2MSFTNGP14.phx.gbl...
>
You can see the cookies for the site in the browser options to make sure
this is not another problem (for example an non protected page)..
Patrice
"Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
news:43ddf678$0$12843$ba620dc5@.text.nova.planet.nl...
> tested again, indeed, even while i have persistance set to false, on
browser
> restart it never passes the login page.
>
> "Edwin Knoppert" <news@.hellobasic.com> schreef in bericht
> news:43ddf3fb$0$12849$ba620dc5@.text.nova.planet.nl...
cookie)...
authentication.
>
I have checked, my options guides me to the folder: ....Local
Settings\Temporary Internet Files
I cleaned most of it, cookies do not show a name i used for test: <forms
name="AuthCookie_logintest1" ...
I assume the cookie *filename* contains the forms name somehow?
Yes, i'm using roles, it all works out fine, i checked with isinrole() on a
2nd webpage.
To authenicate i'm using:
Dim authTicket As FormsAuthenticationTicket = New
FormsAuthenticationTicket(1, sUserName, DateTime.Now, Expiration,
bIsPersistant, sRoles)
Where bIsPersistant is false (checked).
I even terminated the local webserver, the one executed by VWD.
But since i do not persist, i don't think there is a filename right?
"Patrice" <a@.bc.c> schreef in bericht
news:OUd1BWZJGHA.3408@.TK2MSFTNGP12.phx.gbl...
> You can see the cookies for the site in the browser options to make sure
> this is not another problem (for example an non protected page)..
> --
> Patrice
> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
> news:43ddf678$0$12843$ba620dc5@.text.nova.planet.nl...
> browser
> cookie)...
> authentication.
>
Why don't you use Session State? It behaves exactly the same (except for
timing out), and in fact, when it uses cookies, it uses a non-persistent
("session") cookie to identify the client.
More information: All you need to do to not persist a cookie is not to set
the Expiration property. This creates a session cookie on the client, which
is not stored in the file system, but in browser memory. The difference
between using a session cookie on the client,and using Session State, is
that Session State times out. The client session cookie will remain on the
client until the domain is navigated away from, or the browser is closed.
HTH,
Kevin Spencer
Microsoft MVP
.Net Developer
Who is Mighty Abbott?
A twin turret scalawag.
"Edwin Knoppert" <news@.hellobasic.com> wrote in message
news:43de087e$0$12833$ba620dc5@.text.nova.planet.nl...
>I have checked, my options guides me to the folder: ....Local
>Settings\Temporary Internet Files
> I cleaned most of it, cookies do not show a name i used for test: <forms
> name="AuthCookie_logintest1" ...
> I assume the cookie *filename* contains the forms name somehow?
> Yes, i'm using roles, it all works out fine, i checked with isinrole() on
> a 2nd webpage.
> To authenicate i'm using:
> Dim authTicket As FormsAuthenticationTicket = New
> FormsAuthenticationTicket(1, sUserName, DateTime.Now, Expiration,
> bIsPersistant, sRoles)
> Where bIsPersistant is false (checked).
> I even terminated the local webserver, the one executed by VWD.
> But since i do not persist, i don't think there is a filename right?
>
> "Patrice" <a@.bc.c> schreef in bericht
> news:OUd1BWZJGHA.3408@.TK2MSFTNGP12.phx.gbl...
>
I'll look into that tomorrow.
I had a heavy discussion last w that colleagues of mine are misusing
session variables.
I don't want, if the session expires, the user get's bothered to log in
again.
I know, authentication is NOT session related, but my colleagues are
misusing the session object to store a user id into.
I have hard time to talk them into better use.
If the session expires and your o so precious variable got lost, make sure
you reload it and let the client continue with it's request.
But.. i got warned that they don't want to keep authentication 'open' for a
long period of time.
I used to set a month ahead and the auto-expire-increase stuff (forgot) so
the user was never bothered with a login again.
But now they want to use a time-out and force a login.
So i tested it today how it behavious.
Fine by me, important to me is that they should understand the session stuff
first.
Am i right on this?
"Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
news:%23%23$LofcJGHA.3064@.TK2MSFTNGP10.phx.gbl...
> Why don't you use Session State? It behaves exactly the same (except for
> timing out), and in fact, when it uses cookies, it uses a non-persistent
> ("session") cookie to identify the client.
> More information: All you need to do to not persist a cookie is not to set
> the Expiration property. This creates a session cookie on the client,
> which is not stored in the file system, but in browser memory. The
> difference between using a session cookie on the client,and using Session
> State, is that Session State times out. The client session cookie will
> remain on the client until the domain is navigated away from, or the
> browser is closed.
> --
> HTH,
> Kevin Spencer
> Microsoft MVP
> .Net Developer
> Who is Mighty Abbott?
> A twin turret scalawag.
> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
> news:43de087e$0$12833$ba620dc5@.text.nova.planet.nl...
>
> Am i right on this?
I would say yes. In fact, since you are wanting a timeout, Session is
actually the best solution for you.
HTH,
Kevin Spencer
Microsoft MVP
.Net Developer
Who is Mighty Abbott?
A twin turret scalawag.
"Edwin Knoppert" <info@.pbsoft.speedlinq.nl> wrote in message
news:drm3fp$d4a$1@.azure.qinip.net...
> I'll look into that tomorrow.
> I had a heavy discussion last w that colleagues of mine are misusing
> session variables.
> I don't want, if the session expires, the user get's bothered to log in
> again.
> I know, authentication is NOT session related, but my colleagues are
> misusing the session object to store a user id into.
> I have hard time to talk them into better use.
> If the session expires and your o so precious variable got lost, make sure
> you reload it and let the client continue with it's request.
> But.. i got warned that they don't want to keep authentication 'open' for
> a long period of time.
> I used to set a month ahead and the auto-expire-increase stuff (forgot) so
> the user was never bothered with a login again.
> But now they want to use a time-out and force a login.
> So i tested it today how it behavious.
> Fine by me, important to me is that they should understand the session
> stuff first.
> Am i right on this?
>
>
>
>
> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
> news:%23%23$LofcJGHA.3064@.TK2MSFTNGP10.phx.gbl...
>
But.. that's quiet the opposite to what i meant.
I mean, you could use this 'trick' via a session but what i want is that the
session is not used for kinds of stuff.
The expiration of the authentication is not involved with the session so one
actually should use the authentication stuff to reach his goal right?
Expiration in a cookie can work the same as session expiring.
Like i said, using the session and making the client depending on it is a
bad approach imo.
"Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
news:%23EO4OMfJGHA.3936@.TK2MSFTNGP10.phx.gbl...
> I would say yes. In fact, since you are wanting a timeout, Session is
> actually the best solution for you.
> --
> HTH,
> Kevin Spencer
> Microsoft MVP
> .Net Developer
> Who is Mighty Abbott?
> A twin turret scalawag.
>
> "Edwin Knoppert" <info@.pbsoft.speedlinq.nl> wrote in message
> news:drm3fp$d4a$1@.azure.qinip.net...
>

persistant cookie, what is it?

I have searched but info is limitted.

In my test app i used a non persistant cookie for forms authentication.
slidingExpiration is set to true

On run and close and rerun the login remains ok.

I have a time-out of one minute and indeed, it directs me to the login if i
wait to long.
The slidingExpiration does it's work also.

So were is this persistance for?

Thanks,What do you mean by "close" ? A non persistant cookie shouldn't survive when
the browser is closed and launched again (unlike a persistant cookie)...

--

Patrice

"Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl ...
> I have searched but info is limitted.
> In my test app i used a non persistant cookie for forms authentication.
> slidingExpiration is set to true
> On run and close and rerun the login remains ok.
> I have a time-out of one minute and indeed, it directs me to the login if
i
> wait to long.
> The slidingExpiration does it's work also.
> So were is this persistance for?
> Thanks,
Well it does..

And indeed i mean run, close the browser, and run again.
But then this was all tested in the VWD environment.

What you are telling me is what i expected.
In our case we might choose for non-persistance.

"Patrice" <a@.bc.c> schreef in bericht
news:OC1VTrYJGHA.1728@.TK2MSFTNGP14.phx.gbl...
> What do you mean by "close" ? A non persistant cookie shouldn't survive
> when
> the browser is closed and launched again (unlike a persistant cookie)...
> --
> Patrice
> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
> news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl ...
>> I have searched but info is limitted.
>>
>> In my test app i used a non persistant cookie for forms authentication.
>> slidingExpiration is set to true
>>
>> On run and close and rerun the login remains ok.
>>
>> I have a time-out of one minute and indeed, it directs me to the login if
> i
>> wait to long.
>> The slidingExpiration does it's work also.
>>
>> So were is this persistance for?
>>
>> Thanks,
>>
>>
>>
tested again, indeed, even while i have persistance set to false, on browser
restart it never passes the login page.

"Edwin Knoppert" <news@.hellobasic.com> schreef in bericht
news:43ddf3fb$0$12849$ba620dc5@.text.nova.planet.nl ...
> Well it does..
> And indeed i mean run, close the browser, and run again.
> But then this was all tested in the VWD environment.
> What you are telling me is what i expected.
> In our case we might choose for non-persistance.
>
> "Patrice" <a@.bc.c> schreef in bericht
> news:OC1VTrYJGHA.1728@.TK2MSFTNGP14.phx.gbl...
>> What do you mean by "close" ? A non persistant cookie shouldn't survive
>> when
>> the browser is closed and launched again (unlike a persistant cookie)...
>>
>> --
>>
>> Patrice
>>
>> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>> news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl ...
>>> I have searched but info is limitted.
>>>
>>> In my test app i used a non persistant cookie for forms authentication.
>>> slidingExpiration is set to true
>>>
>>> On run and close and rerun the login remains ok.
>>>
>>> I have a time-out of one minute and indeed, it directs me to the login
>>> if
>> i
>>> wait to long.
>>> The slidingExpiration does it's work also.
>>>
>>> So were is this persistance for?
>>>
>>> Thanks,
>>>
>>>
>>>
>>
>>
You can see the cookies for the site in the browser options to make sure
this is not another problem (for example an non protected page)..

--
Patrice

"Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
news:43ddf678$0$12843$ba620dc5@.text.nova.planet.nl ...
> tested again, indeed, even while i have persistance set to false, on
browser
> restart it never passes the login page.
>
> "Edwin Knoppert" <news@.hellobasic.com> schreef in bericht
> news:43ddf3fb$0$12849$ba620dc5@.text.nova.planet.nl ...
> > Well it does..
> > And indeed i mean run, close the browser, and run again.
> > But then this was all tested in the VWD environment.
> > What you are telling me is what i expected.
> > In our case we might choose for non-persistance.
> > "Patrice" <a@.bc.c> schreef in bericht
> > news:OC1VTrYJGHA.1728@.TK2MSFTNGP14.phx.gbl...
> >> What do you mean by "close" ? A non persistant cookie shouldn't survive
> >> when
> >> the browser is closed and launched again (unlike a persistant
cookie)...
> >>
> >> --
> >>
> >> Patrice
> >>
> >> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
> >> news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl ...
> >>> I have searched but info is limitted.
> >>>
> >>> In my test app i used a non persistant cookie for forms
authentication.
> >>> slidingExpiration is set to true
> >>>
> >>> On run and close and rerun the login remains ok.
> >>>
> >>> I have a time-out of one minute and indeed, it directs me to the login
> >>> if
> >> i
> >>> wait to long.
> >>> The slidingExpiration does it's work also.
> >>>
> >>> So were is this persistance for?
> >>>
> >>> Thanks,
> >>>
> >>>
> >>>
> >>
> >>
I have checked, my options guides me to the folder: ....Local
Settings\Temporary Internet Files
I cleaned most of it, cookies do not show a name i used for test: <forms
name="AuthCookie_logintest1" ...
I assume the cookie *filename* contains the forms name somehow?

Yes, i'm using roles, it all works out fine, i checked with isinrole() on a
2nd webpage.
To authenicate i'm using:

Dim authTicket As FormsAuthenticationTicket = New
FormsAuthenticationTicket(1, sUserName, DateTime.Now, Expiration,
bIsPersistant, sRoles)
Where bIsPersistant is false (checked).

I even terminated the local webserver, the one executed by VWD.

But since i do not persist, i don't think there is a filename right?

"Patrice" <a@.bc.c> schreef in bericht
news:OUd1BWZJGHA.3408@.TK2MSFTNGP12.phx.gbl...
> You can see the cookies for the site in the browser options to make sure
> this is not another problem (for example an non protected page)..
> --
> Patrice
> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
> news:43ddf678$0$12843$ba620dc5@.text.nova.planet.nl ...
>> tested again, indeed, even while i have persistance set to false, on
> browser
>> restart it never passes the login page.
>>
>>
>> "Edwin Knoppert" <news@.hellobasic.com> schreef in bericht
>> news:43ddf3fb$0$12849$ba620dc5@.text.nova.planet.nl ...
>> > Well it does..
>>> > And indeed i mean run, close the browser, and run again.
>> > But then this was all tested in the VWD environment.
>>> > What you are telling me is what i expected.
>> > In our case we might choose for non-persistance.
>>>> > "Patrice" <a@.bc.c> schreef in bericht
>> > news:OC1VTrYJGHA.1728@.TK2MSFTNGP14.phx.gbl...
>> >> What do you mean by "close" ? A non persistant cookie shouldn't
>> >> survive
>> >> when
>> >> the browser is closed and launched again (unlike a persistant
> cookie)...
>> >>
>> >> --
>> >>
>> >> Patrice
>> >>
>> >> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>> >> news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl ...
>> >>> I have searched but info is limitted.
>> >>>
>> >>> In my test app i used a non persistant cookie for forms
> authentication.
>> >>> slidingExpiration is set to true
>> >>>
>> >>> On run and close and rerun the login remains ok.
>> >>>
>> >>> I have a time-out of one minute and indeed, it directs me to the
>> >>> login
>> >>> if
>> >> i
>> >>> wait to long.
>> >>> The slidingExpiration does it's work also.
>> >>>
>> >>> So were is this persistance for?
>> >>>
>> >>> Thanks,
>> >>>
>> >>>
>> >>>
>> >>
>> >>
>>>>
>>
Why don't you use Session State? It behaves exactly the same (except for
timing out), and in fact, when it uses cookies, it uses a non-persistent
("session") cookie to identify the client.

More information: All you need to do to not persist a cookie is not to set
the Expiration property. This creates a session cookie on the client, which
is not stored in the file system, but in browser memory. The difference
between using a session cookie on the client,and using Session State, is
that Session State times out. The client session cookie will remain on the
client until the domain is navigated away from, or the browser is closed.

--
HTH,

Kevin Spencer
Microsoft MVP
..Net Developer
Who is Mighty Abbott?
A twin turret scalawag.

"Edwin Knoppert" <news@.hellobasic.com> wrote in message
news:43de087e$0$12833$ba620dc5@.text.nova.planet.nl ...
>I have checked, my options guides me to the folder: ....Local
>Settings\Temporary Internet Files
> I cleaned most of it, cookies do not show a name i used for test: <forms
> name="AuthCookie_logintest1" ...
> I assume the cookie *filename* contains the forms name somehow?
> Yes, i'm using roles, it all works out fine, i checked with isinrole() on
> a 2nd webpage.
> To authenicate i'm using:
> Dim authTicket As FormsAuthenticationTicket = New
> FormsAuthenticationTicket(1, sUserName, DateTime.Now, Expiration,
> bIsPersistant, sRoles)
> Where bIsPersistant is false (checked).
> I even terminated the local webserver, the one executed by VWD.
> But since i do not persist, i don't think there is a filename right?
>
> "Patrice" <a@.bc.c> schreef in bericht
> news:OUd1BWZJGHA.3408@.TK2MSFTNGP12.phx.gbl...
>> You can see the cookies for the site in the browser options to make sure
>> this is not another problem (for example an non protected page)..
>>
>> --
>> Patrice
>>
>> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>> news:43ddf678$0$12843$ba620dc5@.text.nova.planet.nl ...
>>> tested again, indeed, even while i have persistance set to false, on
>> browser
>>> restart it never passes the login page.
>>>
>>>
>>> "Edwin Knoppert" <news@.hellobasic.com> schreef in bericht
>>> news:43ddf3fb$0$12849$ba620dc5@.text.nova.planet.nl ...
>>> > Well it does..
>>>>> > And indeed i mean run, close the browser, and run again.
>>> > But then this was all tested in the VWD environment.
>>>>> > What you are telling me is what i expected.
>>> > In our case we might choose for non-persistance.
>>>>>>> > "Patrice" <a@.bc.c> schreef in bericht
>>> > news:OC1VTrYJGHA.1728@.TK2MSFTNGP14.phx.gbl...
>>> >> What do you mean by "close" ? A non persistant cookie shouldn't
>>> >> survive
>>> >> when
>>> >> the browser is closed and launched again (unlike a persistant
>> cookie)...
>>> >>
>>> >> --
>>> >>
>>> >> Patrice
>>> >>
>>> >> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>>> >> news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl ...
>>> >>> I have searched but info is limitted.
>>> >>>
>>> >>> In my test app i used a non persistant cookie for forms
>> authentication.
>>> >>> slidingExpiration is set to true
>>> >>>
>>> >>> On run and close and rerun the login remains ok.
>>> >>>
>>> >>> I have a time-out of one minute and indeed, it directs me to the
>>> >>> login
>>> >>> if
>>> >> i
>>> >>> wait to long.
>>> >>> The slidingExpiration does it's work also.
>>> >>>
>>> >>> So were is this persistance for?
>>> >>>
>>> >>> Thanks,
>>> >>>
>>> >>>
>>> >>>
>>> >>
>>> >>
>>>>>>>
>>>
>>
>>
I'll look into that tomorrow.

I had a heavy discussion last week that colleagues of mine are misusing
session variables.
I don't want, if the session expires, the user get's bothered to log in
again.
I know, authentication is NOT session related, but my colleagues are
misusing the session object to store a user id into.
I have hard time to talk them into better use.
If the session expires and your o so precious variable got lost, make sure
you reload it and let the client continue with it's request.

But.. i got warned that they don't want to keep authentication 'open' for a
long period of time.
I used to set a month ahead and the auto-expire-increase stuff (forgot) so
the user was never bothered with a login again.
But now they want to use a time-out and force a login.
So i tested it today how it behavious.
Fine by me, important to me is that they should understand the session stuff
first.

Am i right on this?


"Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
news:%23%23$LofcJGHA.3064@.TK2MSFTNGP10.phx.gbl...
> Why don't you use Session State? It behaves exactly the same (except for
> timing out), and in fact, when it uses cookies, it uses a non-persistent
> ("session") cookie to identify the client.
> More information: All you need to do to not persist a cookie is not to set
> the Expiration property. This creates a session cookie on the client,
> which is not stored in the file system, but in browser memory. The
> difference between using a session cookie on the client,and using Session
> State, is that Session State times out. The client session cookie will
> remain on the client until the domain is navigated away from, or the
> browser is closed.
> --
> HTH,
> Kevin Spencer
> Microsoft MVP
> .Net Developer
> Who is Mighty Abbott?
> A twin turret scalawag.
> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
> news:43de087e$0$12833$ba620dc5@.text.nova.planet.nl ...
>>I have checked, my options guides me to the folder: ....Local
>>Settings\Temporary Internet Files
>> I cleaned most of it, cookies do not show a name i used for test: <forms
>> name="AuthCookie_logintest1" ...
>> I assume the cookie *filename* contains the forms name somehow?
>>
>> Yes, i'm using roles, it all works out fine, i checked with isinrole() on
>> a 2nd webpage.
>> To authenicate i'm using:
>>
>> Dim authTicket As FormsAuthenticationTicket = New
>> FormsAuthenticationTicket(1, sUserName, DateTime.Now, Expiration,
>> bIsPersistant, sRoles)
>> Where bIsPersistant is false (checked).
>>
>> I even terminated the local webserver, the one executed by VWD.
>>
>> But since i do not persist, i don't think there is a filename right?
>>
>>
>> "Patrice" <a@.bc.c> schreef in bericht
>> news:OUd1BWZJGHA.3408@.TK2MSFTNGP12.phx.gbl...
>>> You can see the cookies for the site in the browser options to make sure
>>> this is not another problem (for example an non protected page)..
>>>
>>> --
>>> Patrice
>>>
>>> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>>> news:43ddf678$0$12843$ba620dc5@.text.nova.planet.nl ...
>>>> tested again, indeed, even while i have persistance set to false, on
>>> browser
>>>> restart it never passes the login page.
>>>>
>>>>
>>>> "Edwin Knoppert" <news@.hellobasic.com> schreef in bericht
>>>> news:43ddf3fb$0$12849$ba620dc5@.text.nova.planet.nl ...
>>>> > Well it does..
>>>>>>> > And indeed i mean run, close the browser, and run again.
>>>> > But then this was all tested in the VWD environment.
>>>>>>> > What you are telling me is what i expected.
>>>> > In our case we might choose for non-persistance.
>>>>>>>>>> > "Patrice" <a@.bc.c> schreef in bericht
>>>> > news:OC1VTrYJGHA.1728@.TK2MSFTNGP14.phx.gbl...
>>>> >> What do you mean by "close" ? A non persistant cookie shouldn't
>>>> >> survive
>>>> >> when
>>>> >> the browser is closed and launched again (unlike a persistant
>>> cookie)...
>>>> >>
>>>> >> --
>>>> >>
>>>> >> Patrice
>>>> >>
>>>> >> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>>>> >> news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl ...
>>>> >>> I have searched but info is limitted.
>>>> >>>
>>>> >>> In my test app i used a non persistant cookie for forms
>>> authentication.
>>>> >>> slidingExpiration is set to true
>>>> >>>
>>>> >>> On run and close and rerun the login remains ok.
>>>> >>>
>>>> >>> I have a time-out of one minute and indeed, it directs me to the
>>>> >>> login
>>>> >>> if
>>>> >> i
>>>> >>> wait to long.
>>>> >>> The slidingExpiration does it's work also.
>>>> >>>
>>>> >>> So were is this persistance for?
>>>> >>>
>>>> >>> Thanks,
>>>> >>>
>>>> >>>
>>>> >>>
>>>> >>
>>>> >>
>>>>>>>>>>
>>>>
>>>
>>>
>>
>>
> Am i right on this?

I would say yes. In fact, since you are wanting a timeout, Session is
actually the best solution for you.

--
HTH,

Kevin Spencer
Microsoft MVP
..Net Developer
Who is Mighty Abbott?
A twin turret scalawag.

"Edwin Knoppert" <info@.pbsoft.speedlinq.nl> wrote in message
news:drm3fp$d4a$1@.azure.qinip.net...
> I'll look into that tomorrow.
> I had a heavy discussion last week that colleagues of mine are misusing
> session variables.
> I don't want, if the session expires, the user get's bothered to log in
> again.
> I know, authentication is NOT session related, but my colleagues are
> misusing the session object to store a user id into.
> I have hard time to talk them into better use.
> If the session expires and your o so precious variable got lost, make sure
> you reload it and let the client continue with it's request.
> But.. i got warned that they don't want to keep authentication 'open' for
> a long period of time.
> I used to set a month ahead and the auto-expire-increase stuff (forgot) so
> the user was never bothered with a login again.
> But now they want to use a time-out and force a login.
> So i tested it today how it behavious.
> Fine by me, important to me is that they should understand the session
> stuff first.
> Am i right on this?
>
>
>
>
> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
> news:%23%23$LofcJGHA.3064@.TK2MSFTNGP10.phx.gbl...
>> Why don't you use Session State? It behaves exactly the same (except for
>> timing out), and in fact, when it uses cookies, it uses a non-persistent
>> ("session") cookie to identify the client.
>>
>> More information: All you need to do to not persist a cookie is not to
>> set the Expiration property. This creates a session cookie on the client,
>> which is not stored in the file system, but in browser memory. The
>> difference between using a session cookie on the client,and using Session
>> State, is that Session State times out. The client session cookie will
>> remain on the client until the domain is navigated away from, or the
>> browser is closed.
>>
>> --
>> HTH,
>>
>> Kevin Spencer
>> Microsoft MVP
>> .Net Developer
>> Who is Mighty Abbott?
>> A twin turret scalawag.
>>
>> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
>> news:43de087e$0$12833$ba620dc5@.text.nova.planet.nl ...
>>>I have checked, my options guides me to the folder: ....Local
>>>Settings\Temporary Internet Files
>>> I cleaned most of it, cookies do not show a name i used for test: <forms
>>> name="AuthCookie_logintest1" ...
>>> I assume the cookie *filename* contains the forms name somehow?
>>>
>>> Yes, i'm using roles, it all works out fine, i checked with isinrole()
>>> on a 2nd webpage.
>>> To authenicate i'm using:
>>>
>>> Dim authTicket As FormsAuthenticationTicket = New
>>> FormsAuthenticationTicket(1, sUserName, DateTime.Now, Expiration,
>>> bIsPersistant, sRoles)
>>> Where bIsPersistant is false (checked).
>>>
>>> I even terminated the local webserver, the one executed by VWD.
>>>
>>> But since i do not persist, i don't think there is a filename right?
>>>
>>>
>>> "Patrice" <a@.bc.c> schreef in bericht
>>> news:OUd1BWZJGHA.3408@.TK2MSFTNGP12.phx.gbl...
>>>> You can see the cookies for the site in the browser options to make
>>>> sure
>>>> this is not another problem (for example an non protected page)..
>>>>
>>>> --
>>>> Patrice
>>>>
>>>> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>>>> news:43ddf678$0$12843$ba620dc5@.text.nova.planet.nl ...
>>>>> tested again, indeed, even while i have persistance set to false, on
>>>> browser
>>>>> restart it never passes the login page.
>>>>>
>>>>>
>>>>> "Edwin Knoppert" <news@.hellobasic.com> schreef in bericht
>>>>> news:43ddf3fb$0$12849$ba620dc5@.text.nova.planet.nl ...
>>>>> > Well it does..
>>>>>>>>> > And indeed i mean run, close the browser, and run again.
>>>>> > But then this was all tested in the VWD environment.
>>>>>>>>> > What you are telling me is what i expected.
>>>>> > In our case we might choose for non-persistance.
>>>>>>>>>>>>> > "Patrice" <a@.bc.c> schreef in bericht
>>>>> > news:OC1VTrYJGHA.1728@.TK2MSFTNGP14.phx.gbl...
>>>>> >> What do you mean by "close" ? A non persistant cookie shouldn't
>>>>> >> survive
>>>>> >> when
>>>>> >> the browser is closed and launched again (unlike a persistant
>>>> cookie)...
>>>>> >>
>>>>> >> --
>>>>> >>
>>>>> >> Patrice
>>>>> >>
>>>>> >> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>>>>> >> news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl ...
>>>>> >>> I have searched but info is limitted.
>>>>> >>>
>>>>> >>> In my test app i used a non persistant cookie for forms
>>>> authentication.
>>>>> >>> slidingExpiration is set to true
>>>>> >>>
>>>>> >>> On run and close and rerun the login remains ok.
>>>>> >>>
>>>>> >>> I have a time-out of one minute and indeed, it directs me to the
>>>>> >>> login
>>>>> >>> if
>>>>> >> i
>>>>> >>> wait to long.
>>>>> >>> The slidingExpiration does it's work also.
>>>>> >>>
>>>>> >>> So were is this persistance for?
>>>>> >>>
>>>>> >>> Thanks,
>>>>> >>>
>>>>> >>>
>>>>> >>>
>>>>> >>
>>>>> >>
>>>>>>>>>>>>>
>>>>>
>>>>
>>>>
>>>
>>>
>>
>>
But.. that's quiet the opposite to what i meant.

I mean, you could use this 'trick' via a session but what i want is that the
session is not used for kinds of stuff.
The expiration of the authentication is not involved with the session so one
actually should use the authentication stuff to reach his goal right?

Expiration in a cookie can work the same as session expiring.
Like i said, using the session and making the client depending on it is a
bad approach imo.

"Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
news:%23EO4OMfJGHA.3936@.TK2MSFTNGP10.phx.gbl...
>> Am i right on this?
> I would say yes. In fact, since you are wanting a timeout, Session is
> actually the best solution for you.
> --
> HTH,
> Kevin Spencer
> Microsoft MVP
> .Net Developer
> Who is Mighty Abbott?
> A twin turret scalawag.
>
> "Edwin Knoppert" <info@.pbsoft.speedlinq.nl> wrote in message
> news:drm3fp$d4a$1@.azure.qinip.net...
>> I'll look into that tomorrow.
>>
>> I had a heavy discussion last week that colleagues of mine are misusing
>> session variables.
>> I don't want, if the session expires, the user get's bothered to log in
>> again.
>> I know, authentication is NOT session related, but my colleagues are
>> misusing the session object to store a user id into.
>> I have hard time to talk them into better use.
>> If the session expires and your o so precious variable got lost, make
>> sure you reload it and let the client continue with it's request.
>>
>> But.. i got warned that they don't want to keep authentication 'open' for
>> a long period of time.
>> I used to set a month ahead and the auto-expire-increase stuff (forgot)
>> so the user was never bothered with a login again.
>> But now they want to use a time-out and force a login.
>> So i tested it today how it behavious.
>> Fine by me, important to me is that they should understand the session
>> stuff first.
>>
>> Am i right on this?
>>
>>
>>
>>
>>
>>
>>
>>
>>
>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>> news:%23%23$LofcJGHA.3064@.TK2MSFTNGP10.phx.gbl...
>>> Why don't you use Session State? It behaves exactly the same (except for
>>> timing out), and in fact, when it uses cookies, it uses a non-persistent
>>> ("session") cookie to identify the client.
>>>
>>> More information: All you need to do to not persist a cookie is not to
>>> set the Expiration property. This creates a session cookie on the
>>> client, which is not stored in the file system, but in browser memory.
>>> The difference between using a session cookie on the client,and using
>>> Session State, is that Session State times out. The client session
>>> cookie will remain on the client until the domain is navigated away
>>> from, or the browser is closed.
>>>
>>> --
>>> HTH,
>>>
>>> Kevin Spencer
>>> Microsoft MVP
>>> .Net Developer
>>> Who is Mighty Abbott?
>>> A twin turret scalawag.
>>>
>>> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
>>> news:43de087e$0$12833$ba620dc5@.text.nova.planet.nl ...
>>>>I have checked, my options guides me to the folder: ....Local
>>>>Settings\Temporary Internet Files
>>>> I cleaned most of it, cookies do not show a name i used for test:
>>>> <forms name="AuthCookie_logintest1" ...
>>>> I assume the cookie *filename* contains the forms name somehow?
>>>>
>>>> Yes, i'm using roles, it all works out fine, i checked with isinrole()
>>>> on a 2nd webpage.
>>>> To authenicate i'm using:
>>>>
>>>> Dim authTicket As FormsAuthenticationTicket = New
>>>> FormsAuthenticationTicket(1, sUserName, DateTime.Now, Expiration,
>>>> bIsPersistant, sRoles)
>>>> Where bIsPersistant is false (checked).
>>>>
>>>> I even terminated the local webserver, the one executed by VWD.
>>>>
>>>> But since i do not persist, i don't think there is a filename right?
>>>>
>>>>
>>>> "Patrice" <a@.bc.c> schreef in bericht
>>>> news:OUd1BWZJGHA.3408@.TK2MSFTNGP12.phx.gbl...
>>>>> You can see the cookies for the site in the browser options to make
>>>>> sure
>>>>> this is not another problem (for example an non protected page)..
>>>>>
>>>>> --
>>>>> Patrice
>>>>>
>>>>> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>>>>> news:43ddf678$0$12843$ba620dc5@.text.nova.planet.nl ...
>>>>>> tested again, indeed, even while i have persistance set to false, on
>>>>> browser
>>>>>> restart it never passes the login page.
>>>>>>
>>>>>>
>>>>>> "Edwin Knoppert" <news@.hellobasic.com> schreef in bericht
>>>>>> news:43ddf3fb$0$12849$ba620dc5@.text.nova.planet.nl ...
>>>>>> > Well it does..
>>>>>>>>>>> > And indeed i mean run, close the browser, and run again.
>>>>>> > But then this was all tested in the VWD environment.
>>>>>>>>>>> > What you are telling me is what i expected.
>>>>>> > In our case we might choose for non-persistance.
>>>>>>>>>>>>>>>> > "Patrice" <a@.bc.c> schreef in bericht
>>>>>> > news:OC1VTrYJGHA.1728@.TK2MSFTNGP14.phx.gbl...
>>>>>> >> What do you mean by "close" ? A non persistant cookie shouldn't
>>>>>> >> survive
>>>>>> >> when
>>>>>> >> the browser is closed and launched again (unlike a persistant
>>>>> cookie)...
>>>>>> >>
>>>>>> >> --
>>>>>> >>
>>>>>> >> Patrice
>>>>>> >>
>>>>>> >> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>>>>>> >> news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl ...
>>>>>> >>> I have searched but info is limitted.
>>>>>> >>>
>>>>>> >>> In my test app i used a non persistant cookie for forms
>>>>> authentication.
>>>>>> >>> slidingExpiration is set to true
>>>>>> >>>
>>>>>> >>> On run and close and rerun the login remains ok.
>>>>>> >>>
>>>>>> >>> I have a time-out of one minute and indeed, it directs me to the
>>>>>> >>> login
>>>>>> >>> if
>>>>>> >> i
>>>>>> >>> wait to long.
>>>>>> >>> The slidingExpiration does it's work also.
>>>>>> >>>
>>>>>> >>> So were is this persistance for?
>>>>>> >>>
>>>>>> >>> Thanks,
>>>>>> >>>
>>>>>> >>>
>>>>>> >>>
>>>>>> >>
>>>>>> >>
>>>>>>>>>>>>>>>>
>>>>>>
>>>>>
>>>>>
>>>>
>>>>
>>>
>>>
>>
>>
I'm not sure what problem you have with Session State. It is there for a
purpose. "imo" is not a logical reason for doing or not doing something. An
opinion is a poor substitute for a fact. The fact that Session times out
makes it eminently suitable for any user-specific temporary data storage
that should expire within a given time span. That is what it was designed
for.

--
HTH,

Kevin Spencer
Microsoft MVP
..Net Developer
Who is Mighty Abbott?
A twin turret scalawag.

"Edwin Knoppert" <news@.hellobasic.com> wrote in message
news:43df229a$0$12846$ba620dc5@.text.nova.planet.nl ...
> But.. that's quiet the opposite to what i meant.
> I mean, you could use this 'trick' via a session but what i want is that
> the session is not used for kinds of stuff.
> The expiration of the authentication is not involved with the session so
> one actually should use the authentication stuff to reach his goal right?
> Expiration in a cookie can work the same as session expiring.
> Like i said, using the session and making the client depending on it is a
> bad approach imo.
>
>
> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
> news:%23EO4OMfJGHA.3936@.TK2MSFTNGP10.phx.gbl...
>>> Am i right on this?
>>
>> I would say yes. In fact, since you are wanting a timeout, Session is
>> actually the best solution for you.
>>
>> --
>> HTH,
>>
>> Kevin Spencer
>> Microsoft MVP
>> .Net Developer
>> Who is Mighty Abbott?
>> A twin turret scalawag.
>>
>>
>> "Edwin Knoppert" <info@.pbsoft.speedlinq.nl> wrote in message
>> news:drm3fp$d4a$1@.azure.qinip.net...
>>> I'll look into that tomorrow.
>>>
>>> I had a heavy discussion last week that colleagues of mine are misusing
>>> session variables.
>>> I don't want, if the session expires, the user get's bothered to log in
>>> again.
>>> I know, authentication is NOT session related, but my colleagues are
>>> misusing the session object to store a user id into.
>>> I have hard time to talk them into better use.
>>> If the session expires and your o so precious variable got lost, make
>>> sure you reload it and let the client continue with it's request.
>>>
>>> But.. i got warned that they don't want to keep authentication 'open'
>>> for a long period of time.
>>> I used to set a month ahead and the auto-expire-increase stuff (forgot)
>>> so the user was never bothered with a login again.
>>> But now they want to use a time-out and force a login.
>>> So i tested it today how it behavious.
>>> Fine by me, important to me is that they should understand the session
>>> stuff first.
>>>
>>> Am i right on this?
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>>> news:%23%23$LofcJGHA.3064@.TK2MSFTNGP10.phx.gbl...
>>>> Why don't you use Session State? It behaves exactly the same (except
>>>> for timing out), and in fact, when it uses cookies, it uses a
>>>> non-persistent ("session") cookie to identify the client.
>>>>
>>>> More information: All you need to do to not persist a cookie is not to
>>>> set the Expiration property. This creates a session cookie on the
>>>> client, which is not stored in the file system, but in browser memory.
>>>> The difference between using a session cookie on the client,and using
>>>> Session State, is that Session State times out. The client session
>>>> cookie will remain on the client until the domain is navigated away
>>>> from, or the browser is closed.
>>>>
>>>> --
>>>> HTH,
>>>>
>>>> Kevin Spencer
>>>> Microsoft MVP
>>>> .Net Developer
>>>> Who is Mighty Abbott?
>>>> A twin turret scalawag.
>>>>
>>>> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
>>>> news:43de087e$0$12833$ba620dc5@.text.nova.planet.nl ...
>>>>>I have checked, my options guides me to the folder: ....Local
>>>>>Settings\Temporary Internet Files
>>>>> I cleaned most of it, cookies do not show a name i used for test:
>>>>> <forms name="AuthCookie_logintest1" ...
>>>>> I assume the cookie *filename* contains the forms name somehow?
>>>>>
>>>>> Yes, i'm using roles, it all works out fine, i checked with isinrole()
>>>>> on a 2nd webpage.
>>>>> To authenicate i'm using:
>>>>>
>>>>> Dim authTicket As FormsAuthenticationTicket = New
>>>>> FormsAuthenticationTicket(1, sUserName, DateTime.Now, Expiration,
>>>>> bIsPersistant, sRoles)
>>>>> Where bIsPersistant is false (checked).
>>>>>
>>>>> I even terminated the local webserver, the one executed by VWD.
>>>>>
>>>>> But since i do not persist, i don't think there is a filename right?
>>>>>
>>>>>
>>>>> "Patrice" <a@.bc.c> schreef in bericht
>>>>> news:OUd1BWZJGHA.3408@.TK2MSFTNGP12.phx.gbl...
>>>>>> You can see the cookies for the site in the browser options to make
>>>>>> sure
>>>>>> this is not another problem (for example an non protected page)..
>>>>>>
>>>>>> --
>>>>>> Patrice
>>>>>>
>>>>>> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>>>>>> news:43ddf678$0$12843$ba620dc5@.text.nova.planet.nl ...
>>>>>>> tested again, indeed, even while i have persistance set to false, on
>>>>>> browser
>>>>>>> restart it never passes the login page.
>>>>>>>
>>>>>>>
>>>>>>> "Edwin Knoppert" <news@.hellobasic.com> schreef in bericht
>>>>>>> news:43ddf3fb$0$12849$ba620dc5@.text.nova.planet.nl ...
>>>>>>> > Well it does..
>>>>>>>>>>>>> > And indeed i mean run, close the browser, and run again.
>>>>>>> > But then this was all tested in the VWD environment.
>>>>>>>>>>>>> > What you are telling me is what i expected.
>>>>>>> > In our case we might choose for non-persistance.
>>>>>>>>>>>>>>>>>>> > "Patrice" <a@.bc.c> schreef in bericht
>>>>>>> > news:OC1VTrYJGHA.1728@.TK2MSFTNGP14.phx.gbl...
>>>>>>> >> What do you mean by "close" ? A non persistant cookie shouldn't
>>>>>>> >> survive
>>>>>>> >> when
>>>>>>> >> the browser is closed and launched again (unlike a persistant
>>>>>> cookie)...
>>>>>>> >>
>>>>>>> >> --
>>>>>>> >>
>>>>>>> >> Patrice
>>>>>>> >>
>>>>>>> >> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>>>>>>> >> news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl ...
>>>>>>> >>> I have searched but info is limitted.
>>>>>>> >>>
>>>>>>> >>> In my test app i used a non persistant cookie for forms
>>>>>> authentication.
>>>>>>> >>> slidingExpiration is set to true
>>>>>>> >>>
>>>>>>> >>> On run and close and rerun the login remains ok.
>>>>>>> >>>
>>>>>>> >>> I have a time-out of one minute and indeed, it directs me to the
>>>>>>> >>> login
>>>>>>> >>> if
>>>>>>> >> i
>>>>>>> >>> wait to long.
>>>>>>> >>> The slidingExpiration does it's work also.
>>>>>>> >>>
>>>>>>> >>> So were is this persistance for?
>>>>>>> >>>
>>>>>>> >>> Thanks,
>>>>>>> >>>
>>>>>>> >>>
>>>>>>> >>>
>>>>>>> >>
>>>>>>> >>
>>>>>>>>>>>>>>>>>>>
>>>>>>>
>>>>>>
>>>>>>
>>>>>
>>>>>
>>>>
>>>>
>>>
>>>
>>
>>
We have a miscommunication.
I agree on the session state, i read about it, the "sqlserver" solution
might be a good option.

I simply mentioned that the end-user shouldn't be bothered with unwanted
time-outs.
Iow, if a session has a timeout, a new request must be able to produce the
request.

The login stuff, another issue, should never rely on a session object.
If you need a time-out on a authentication, don't use the session but make
sure the authentication itselfs has a time-out.
It's a vision of mine not to use the session object in such a way the user
get's bothered.

When i access hotmail and i go to diner and come back i can continue, unless
my cookie has expired, which is a month or so :)

"Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
news:%23%23ueqCmJGHA.1032@.TK2MSFTNGP11.phx.gbl...
> I'm not sure what problem you have with Session State. It is there for a
> purpose. "imo" is not a logical reason for doing or not doing something.
> An opinion is a poor substitute for a fact. The fact that Session times
> out makes it eminently suitable for any user-specific temporary data
> storage that should expire within a given time span. That is what it was
> designed for.
> --
> HTH,
> Kevin Spencer
> Microsoft MVP
> .Net Developer
> Who is Mighty Abbott?
> A twin turret scalawag.
> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
> news:43df229a$0$12846$ba620dc5@.text.nova.planet.nl ...
>> But.. that's quiet the opposite to what i meant.
>>
>> I mean, you could use this 'trick' via a session but what i want is that
>> the session is not used for kinds of stuff.
>> The expiration of the authentication is not involved with the session so
>> one actually should use the authentication stuff to reach his goal right?
>>
>> Expiration in a cookie can work the same as session expiring.
>> Like i said, using the session and making the client depending on it is a
>> bad approach imo.
>>
>>
>>
>>
>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>> news:%23EO4OMfJGHA.3936@.TK2MSFTNGP10.phx.gbl...
>>>> Am i right on this?
>>>
>>> I would say yes. In fact, since you are wanting a timeout, Session is
>>> actually the best solution for you.
>>>
>>> --
>>> HTH,
>>>
>>> Kevin Spencer
>>> Microsoft MVP
>>> .Net Developer
>>> Who is Mighty Abbott?
>>> A twin turret scalawag.
>>>
>>>
>>> "Edwin Knoppert" <info@.pbsoft.speedlinq.nl> wrote in message
>>> news:drm3fp$d4a$1@.azure.qinip.net...
>>>> I'll look into that tomorrow.
>>>>
>>>> I had a heavy discussion last week that colleagues of mine are misusing
>>>> session variables.
>>>> I don't want, if the session expires, the user get's bothered to log in
>>>> again.
>>>> I know, authentication is NOT session related, but my colleagues are
>>>> misusing the session object to store a user id into.
>>>> I have hard time to talk them into better use.
>>>> If the session expires and your o so precious variable got lost, make
>>>> sure you reload it and let the client continue with it's request.
>>>>
>>>> But.. i got warned that they don't want to keep authentication 'open'
>>>> for a long period of time.
>>>> I used to set a month ahead and the auto-expire-increase stuff (forgot)
>>>> so the user was never bothered with a login again.
>>>> But now they want to use a time-out and force a login.
>>>> So i tested it today how it behavious.
>>>> Fine by me, important to me is that they should understand the session
>>>> stuff first.
>>>>
>>>> Am i right on this?
>>>>
>>>>
>>>>
>>>>
>>>>
>>>>
>>>>
>>>>
>>>>
>>>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>>>> news:%23%23$LofcJGHA.3064@.TK2MSFTNGP10.phx.gbl...
>>>>> Why don't you use Session State? It behaves exactly the same (except
>>>>> for timing out), and in fact, when it uses cookies, it uses a
>>>>> non-persistent ("session") cookie to identify the client.
>>>>>
>>>>> More information: All you need to do to not persist a cookie is not to
>>>>> set the Expiration property. This creates a session cookie on the
>>>>> client, which is not stored in the file system, but in browser memory.
>>>>> The difference between using a session cookie on the client,and using
>>>>> Session State, is that Session State times out. The client session
>>>>> cookie will remain on the client until the domain is navigated away
>>>>> from, or the browser is closed.
>>>>>
>>>>> --
>>>>> HTH,
>>>>>
>>>>> Kevin Spencer
>>>>> Microsoft MVP
>>>>> .Net Developer
>>>>> Who is Mighty Abbott?
>>>>> A twin turret scalawag.
>>>>>
>>>>> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
>>>>> news:43de087e$0$12833$ba620dc5@.text.nova.planet.nl ...
>>>>>>I have checked, my options guides me to the folder: ....Local
>>>>>>Settings\Temporary Internet Files
>>>>>> I cleaned most of it, cookies do not show a name i used for test:
>>>>>> <forms name="AuthCookie_logintest1" ...
>>>>>> I assume the cookie *filename* contains the forms name somehow?
>>>>>>
>>>>>> Yes, i'm using roles, it all works out fine, i checked with
>>>>>> isinrole() on a 2nd webpage.
>>>>>> To authenicate i'm using:
>>>>>>
>>>>>> Dim authTicket As FormsAuthenticationTicket = New
>>>>>> FormsAuthenticationTicket(1, sUserName, DateTime.Now, Expiration,
>>>>>> bIsPersistant, sRoles)
>>>>>> Where bIsPersistant is false (checked).
>>>>>>
>>>>>> I even terminated the local webserver, the one executed by VWD.
>>>>>>
>>>>>> But since i do not persist, i don't think there is a filename right?
>>>>>>
>>>>>>
>>>>>> "Patrice" <a@.bc.c> schreef in bericht
>>>>>> news:OUd1BWZJGHA.3408@.TK2MSFTNGP12.phx.gbl...
>>>>>>> You can see the cookies for the site in the browser options to make
>>>>>>> sure
>>>>>>> this is not another problem (for example an non protected page)..
>>>>>>>
>>>>>>> --
>>>>>>> Patrice
>>>>>>>
>>>>>>> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message de
>>>>>>> news:43ddf678$0$12843$ba620dc5@.text.nova.planet.nl ...
>>>>>>>> tested again, indeed, even while i have persistance set to false,
>>>>>>>> on
>>>>>>> browser
>>>>>>>> restart it never passes the login page.
>>>>>>>>
>>>>>>>>
>>>>>>>> "Edwin Knoppert" <news@.hellobasic.com> schreef in bericht
>>>>>>>> news:43ddf3fb$0$12849$ba620dc5@.text.nova.planet.nl ...
>>>>>>>> > Well it does..
>>>>>>>>>>>>>>> > And indeed i mean run, close the browser, and run again.
>>>>>>>> > But then this was all tested in the VWD environment.
>>>>>>>>>>>>>>> > What you are telling me is what i expected.
>>>>>>>> > In our case we might choose for non-persistance.
>>>>>>>>>>>>>>>>>>>>>> > "Patrice" <a@.bc.c> schreef in bericht
>>>>>>>> > news:OC1VTrYJGHA.1728@.TK2MSFTNGP14.phx.gbl...
>>>>>>>> >> What do you mean by "close" ? A non persistant cookie shouldn't
>>>>>>>> >> survive
>>>>>>>> >> when
>>>>>>>> >> the browser is closed and launched again (unlike a persistant
>>>>>>> cookie)...
>>>>>>>> >>
>>>>>>>> >> --
>>>>>>>> >>
>>>>>>>> >> Patrice
>>>>>>>> >>
>>>>>>>> >> "Edwin Knoppert" <news@.hellobasic.com> a crit dans le message
>>>>>>>> >> de
>>>>>>>> >> news:43ddeb0e$0$12848$ba620dc5@.text.nova.planet.nl ...
>>>>>>>> >>> I have searched but info is limitted.
>>>>>>>> >>>
>>>>>>>> >>> In my test app i used a non persistant cookie for forms
>>>>>>> authentication.
>>>>>>>> >>> slidingExpiration is set to true
>>>>>>>> >>>
>>>>>>>> >>> On run and close and rerun the login remains ok.
>>>>>>>> >>>
>>>>>>>> >>> I have a time-out of one minute and indeed, it directs me to
>>>>>>>> >>> the login
>>>>>>>> >>> if
>>>>>>>> >> i
>>>>>>>> >>> wait to long.
>>>>>>>> >>> The slidingExpiration does it's work also.
>>>>>>>> >>>
>>>>>>>> >>> So were is this persistance for?
>>>>>>>> >>>
>>>>>>>> >>> Thanks,
>>>>>>>> >>>
>>>>>>>> >>>
>>>>>>>> >>>
>>>>>>>> >>
>>>>>>>> >>
>>>>>>>>>>>>>>>>>>>>>>
>>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>
>>>>>>
>>>>>
>>>>>
>>>>
>>>>
>>>
>>>
>>
>>
Hi Edwin,

Perhaps I'm just misunderstanding your requirements. When you said "now they
want to use a time-out and force a login" I understood you to mean that a
literal timeout would be necessary. But when you say "When i access hotmail
and i go to diner and come back i can continue, unless my cookie has
expired, which is a month or so" I understand you to say that you do *not*
need to use a timeout.

Here's the crux of the issue: If you want to timeout the user during a
browser session, Session State is the way to go. If you want to not require
the user to log in for a month, a persistent cookie is the way to go. If you
want the user to not time out, but to be logged out when he/sh closes the
browser, a non-persistent (session) cookie is the way to go.

Again, I don't understand what your requirements are. However, here are some
security considerations to take into account when creating requirements.

If you use anything but a server timeout (such as Session) you take a
security risk. For example, if you use a session cookie, which does not
expire as long as the browser remains opened, the user can leave, and
another person can come and work on the same computer with that user's
stuff. This is even worse if you set the expiration for some date in the
future, as anyone that browses to the domain on that computer will be
automatically logged in.

--
HTH,

Kevin Spencer
Microsoft MVP
..Net Developer
Who is Mighty Abbott?
A twin turret scalawag.

"Edwin Knoppert" <news@.hellobasic.com> wrote in message
news:43df5f39$0$1631$ba620dc5@.text.nova.planet.nl. ..
> We have a miscommunication.
> I agree on the session state, i read about it, the "sqlserver" solution
> might be a good option.
> I simply mentioned that the end-user shouldn't be bothered with unwanted
> time-outs.
> Iow, if a session has a timeout, a new request must be able to produce the
> request.
> The login stuff, another issue, should never rely on a session object.
> If you need a time-out on a authentication, don't use the session but make
> sure the authentication itselfs has a time-out.
> It's a vision of mine not to use the session object in such a way the user
> get's bothered.
> When i access hotmail and i go to diner and come back i can continue,
> unless my cookie has expired, which is a month or so :)
>
>
> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
> news:%23%23ueqCmJGHA.1032@.TK2MSFTNGP11.phx.gbl...
>> I'm not sure what problem you have with Session State. It is there for a
>> purpose. "imo" is not a logical reason for doing or not doing something.
>> An opinion is a poor substitute for a fact. The fact that Session times
>> out makes it eminently suitable for any user-specific temporary data
>> storage that should expire within a given time span. That is what it was
>> designed for.
>>
>> --
>> HTH,
>>
>> Kevin Spencer
>> Microsoft MVP
>> .Net Developer
>> Who is Mighty Abbott?
>> A twin turret scalawag.
>>
>> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
>> news:43df229a$0$12846$ba620dc5@.text.nova.planet.nl ...
>>> But.. that's quiet the opposite to what i meant.
>>>
>>> I mean, you could use this 'trick' via a session but what i want is that
>>> the session is not used for kinds of stuff.
>>> The expiration of the authentication is not involved with the session so
>>> one actually should use the authentication stuff to reach his goal
>>> right?
>>>
>>> Expiration in a cookie can work the same as session expiring.
>>> Like i said, using the session and making the client depending on it is
>>> a bad approach imo.
>>>
>>>
>>>
>>>
>>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>>> news:%23EO4OMfJGHA.3936@.TK2MSFTNGP10.phx.gbl...
>>>>> Am i right on this?
>>>>
>>>> I would say yes. In fact, since you are wanting a timeout, Session is
>>>> actually the best solution for you.
>>>>
>>>> --
>>>> HTH,
>>>>
>>>> Kevin Spencer
>>>> Microsoft MVP
>>>> .Net Developer
>>>> Who is Mighty Abbott?
>>>> A twin turret scalawag.
>>>>
>>>>
>>>> "Edwin Knoppert" <info@.pbsoft.speedlinq.nl> wrote in message
>>>> news:drm3fp$d4a$1@.azure.qinip.net...
>>>>> I'll look into that tomorrow.
>>>>>
>>>>> I had a heavy discussion last week that colleagues of mine are
>>>>> misusing session variables.
>>>>> I don't want, if the session expires, the user get's bothered to log
>>>>> in again.
>>>>> I know, authentication is NOT session related, but my colleagues are
>>>>> misusing the session object to store a user id into.
>>>>> I have hard time to talk them into better use.
>>>>> If the session expires and your o so precious variable got lost, make
>>>>> sure you reload it and let the client continue with it's request.
>>>>>
>>>>> But.. i got warned that they don't want to keep authentication 'open'
>>>>> for a long period of time.
>>>>> I used to set a month ahead and the auto-expire-increase stuff
>>>>> (forgot) so the user was never bothered with a login again.
>>>>> But now they want to use a time-out and force a login.
>>>>> So i tested it today how it behavious.
>>>>> Fine by me, important to me is that they should understand the session
>>>>> stuff first.
>>>>>
>>>>> Am i right on this?
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>>>>> news:%23%23$LofcJGHA.3064@.TK2MSFTNGP10.phx.gbl...
>>>>>> Why don't you use Session State? It behaves exactly the same (except
>>>>>> for timing out), and in fact, when it uses cookies, it uses a
>>>>>> non-persistent ("session") cookie to identify the client.
>>>>>>
>>>>>> More information: All you need to do to not persist a cookie is not
>>>>>> to set the Expiration property. This creates a session cookie on the
>>>>>> client, which is not stored in the file system, but in browser
>>>>>> memory. The difference between using a session cookie on the
>>>>>> client,and using Session State, is that Session State times out. The
>>>>>> client session cookie will remain on the client until the domain is
>>>>>> navigated away from, or the browser is closed.
>>>>>>
>>>>>> --
>>>>>> HTH,
>>>>>>
>>>>>> Kevin Spencer
>>>>>> Microsoft MVP
>>>>>> .Net Developer
>>>>>> Who is Mighty Abbott?
>>>>>> A twin turret scalawag.
Thanks,

I'm do not entirly agree, in this case yes but if an app is critical, like
finacial/private or so, for myself i abandon my making use of signoff()
stuff.
Like i said, i was used to cookies set for a month, now i set it to
15minutes and slidingexpiration.
So that 'could' be seen simialr to session expiring.
If you leave the computer and someone can start the browser and continue..
well it's their choice to leave the browser unprotected.

But now i think of it.. maybe the cookieless or similar stuff is the best
thing to do.
I have no experiance with that yet but i wouldn't see an odd session id in
my url..

Still, to be persistant, i would not use the session to be the time-out, it
has nothing to do with authentication, maybe internally or indirect but not
for me as programmer.
If the admin chooses to increase or decrease session time-out i would not
want to be depending on that for the authentication matter.
Even so, if we would be 'superfriendly' we even could ask the client for a
authentication time-out.
yes, that would then require a cookie to be stored.. i know.

Authentication ISNOT session... clear?
:)

"Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
news:uwaVoApJGHA.2708@.tk2msftngp13.phx.gbl...
> Hi Edwin,
> Perhaps I'm just misunderstanding your requirements. When you said "now
> they want to use a time-out and force a login" I understood you to mean
> that a literal timeout would be necessary. But when you say "When i access
> hotmail and i go to diner and come back i can continue, unless my cookie
> has expired, which is a month or so" I understand you to say that you do
> *not* need to use a timeout.
> Here's the crux of the issue: If you want to timeout the user during a
> browser session, Session State is the way to go. If you want to not
> require the user to log in for a month, a persistent cookie is the way to
> go. If you want the user to not time out, but to be logged out when he/sh
> closes the browser, a non-persistent (session) cookie is the way to go.
> Again, I don't understand what your requirements are. However, here are
> some security considerations to take into account when creating
> requirements.
> If you use anything but a server timeout (such as Session) you take a
> security risk. For example, if you use a session cookie, which does not
> expire as long as the browser remains opened, the user can leave, and
> another person can come and work on the same computer with that user's
> stuff. This is even worse if you set the expiration for some date in the
> future, as anyone that browses to the domain on that computer will be
> automatically logged in.
> --
> HTH,
> Kevin Spencer
> Microsoft MVP
> .Net Developer
> Who is Mighty Abbott?
> A twin turret scalawag.
>
> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
> news:43df5f39$0$1631$ba620dc5@.text.nova.planet.nl. ..
>> We have a miscommunication.
>> I agree on the session state, i read about it, the "sqlserver" solution
>> might be a good option.
>>
>> I simply mentioned that the end-user shouldn't be bothered with unwanted
>> time-outs.
>> Iow, if a session has a timeout, a new request must be able to produce
>> the request.
>>
>> The login stuff, another issue, should never rely on a session object.
>> If you need a time-out on a authentication, don't use the session but
>> make sure the authentication itselfs has a time-out.
>> It's a vision of mine not to use the session object in such a way the
>> user get's bothered.
>>
>> When i access hotmail and i go to diner and come back i can continue,
>> unless my cookie has expired, which is a month or so :)
>>
>>
>>
>>
>>
>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>> news:%23%23ueqCmJGHA.1032@.TK2MSFTNGP11.phx.gbl...
>>> I'm not sure what problem you have with Session State. It is there for a
>>> purpose. "imo" is not a logical reason for doing or not doing something.
>>> An opinion is a poor substitute for a fact. The fact that Session times
>>> out makes it eminently suitable for any user-specific temporary data
>>> storage that should expire within a given time span. That is what it was
>>> designed for.
>>>
>>> --
>>> HTH,
>>>
>>> Kevin Spencer
>>> Microsoft MVP
>>> .Net Developer
>>> Who is Mighty Abbott?
>>> A twin turret scalawag.
>>>
>>> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
>>> news:43df229a$0$12846$ba620dc5@.text.nova.planet.nl ...
>>>> But.. that's quiet the opposite to what i meant.
>>>>
>>>> I mean, you could use this 'trick' via a session but what i want is
>>>> that the session is not used for kinds of stuff.
>>>> The expiration of the authentication is not involved with the session
>>>> so one actually should use the authentication stuff to reach his goal
>>>> right?
>>>>
>>>> Expiration in a cookie can work the same as session expiring.
>>>> Like i said, using the session and making the client depending on it is
>>>> a bad approach imo.
>>>>
>>>>
>>>>
>>>>
>>>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>>>> news:%23EO4OMfJGHA.3936@.TK2MSFTNGP10.phx.gbl...
>>>>>> Am i right on this?
>>>>>
>>>>> I would say yes. In fact, since you are wanting a timeout, Session is
>>>>> actually the best solution for you.
>>>>>
>>>>> --
>>>>> HTH,
>>>>>
>>>>> Kevin Spencer
>>>>> Microsoft MVP
>>>>> .Net Developer
>>>>> Who is Mighty Abbott?
>>>>> A twin turret scalawag.
>>>>>
>>>>>
>>>>> "Edwin Knoppert" <info@.pbsoft.speedlinq.nl> wrote in message
>>>>> news:drm3fp$d4a$1@.azure.qinip.net...
>>>>>> I'll look into that tomorrow.
>>>>>>
>>>>>> I had a heavy discussion last week that colleagues of mine are
>>>>>> misusing session variables.
>>>>>> I don't want, if the session expires, the user get's bothered to log
>>>>>> in again.
>>>>>> I know, authentication is NOT session related, but my colleagues are
>>>>>> misusing the session object to store a user id into.
>>>>>> I have hard time to talk them into better use.
>>>>>> If the session expires and your o so precious variable got lost, make
>>>>>> sure you reload it and let the client continue with it's request.
>>>>>>
>>>>>> But.. i got warned that they don't want to keep authentication 'open'
>>>>>> for a long period of time.
>>>>>> I used to set a month ahead and the auto-expire-increase stuff
>>>>>> (forgot) so the user was never bothered with a login again.
>>>>>> But now they want to use a time-out and force a login.
>>>>>> So i tested it today how it behavious.
>>>>>> Fine by me, important to me is that they should understand the
>>>>>> session stuff first.
>>>>>>
>>>>>> Am i right on this?
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>>>>>> news:%23%23$LofcJGHA.3064@.TK2MSFTNGP10.phx.gbl...
>>>>>>> Why don't you use Session State? It behaves exactly the same (except
>>>>>>> for timing out), and in fact, when it uses cookies, it uses a
>>>>>>> non-persistent ("session") cookie to identify the client.
>>>>>>>
>>>>>>> More information: All you need to do to not persist a cookie is not
>>>>>>> to set the Expiration property. This creates a session cookie on the
>>>>>>> client, which is not stored in the file system, but in browser
>>>>>>> memory. The difference between using a session cookie on the
>>>>>>> client,and using Session State, is that Session State times out. The
>>>>>>> client session cookie will remain on the client until the domain is
>>>>>>> navigated away from, or the browser is closed.
>>>>>>>
>>>>>>> --
>>>>>>> HTH,
>>>>>>>
>>>>>>> Kevin Spencer
>>>>>>> Microsoft MVP
>>>>>>> .Net Developer
>>>>>>> Who is Mighty Abbott?
>>>>>>> A twin turret scalawag.
> Authentication ISNOT session... clear?

Not really. That's sort of like saying that a chimney is not like a brick.

But as long as *you're* clear, that's all that matters!

--
HTH,

Kevin Spencer
Microsoft MVP
..Net Developer
Who is Mighty Abbott?
A twin turret scalawag.

"Edwin Knoppert" <info@.pbsoft.speedlinq.nl> wrote in message
news:drok2b$941$1@.azure.qinip.net...
> Thanks,
> I'm do not entirly agree, in this case yes but if an app is critical, like
> finacial/private or so, for myself i abandon my making use of signoff()
> stuff.
> Like i said, i was used to cookies set for a month, now i set it to
> 15minutes and slidingexpiration.
> So that 'could' be seen simialr to session expiring.
> If you leave the computer and someone can start the browser and continue..
> well it's their choice to leave the browser unprotected.
> But now i think of it.. maybe the cookieless or similar stuff is the best
> thing to do.
> I have no experiance with that yet but i wouldn't see an odd session id in
> my url..
> Still, to be persistant, i would not use the session to be the time-out,
> it has nothing to do with authentication, maybe internally or indirect but
> not for me as programmer.
> If the admin chooses to increase or decrease session time-out i would not
> want to be depending on that for the authentication matter.
> Even so, if we would be 'superfriendly' we even could ask the client for a
> authentication time-out.
> yes, that would then require a cookie to be stored.. i know.
> Authentication ISNOT session... clear?
> :)
>
>
> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
> news:uwaVoApJGHA.2708@.tk2msftngp13.phx.gbl...
>> Hi Edwin,
>>
>> Perhaps I'm just misunderstanding your requirements. When you said "now
>> they want to use a time-out and force a login" I understood you to mean
>> that a literal timeout would be necessary. But when you say "When i
>> access hotmail and i go to diner and come back i can continue, unless my
>> cookie has expired, which is a month or so" I understand you to say that
>> you do *not* need to use a timeout.
>>
>> Here's the crux of the issue: If you want to timeout the user during a
>> browser session, Session State is the way to go. If you want to not
>> require the user to log in for a month, a persistent cookie is the way to
>> go. If you want the user to not time out, but to be logged out when he/sh
>> closes the browser, a non-persistent (session) cookie is the way to go.
>>
>> Again, I don't understand what your requirements are. However, here are
>> some security considerations to take into account when creating
>> requirements.
>>
>> If you use anything but a server timeout (such as Session) you take a
>> security risk. For example, if you use a session cookie, which does not
>> expire as long as the browser remains opened, the user can leave, and
>> another person can come and work on the same computer with that user's
>> stuff. This is even worse if you set the expiration for some date in the
>> future, as anyone that browses to the domain on that computer will be
>> automatically logged in.
>>
>> --
>> HTH,
>>
>> Kevin Spencer
>> Microsoft MVP
>> .Net Developer
>> Who is Mighty Abbott?
>> A twin turret scalawag.
>>
>>
>> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
>> news:43df5f39$0$1631$ba620dc5@.text.nova.planet.nl. ..
>>> We have a miscommunication.
>>> I agree on the session state, i read about it, the "sqlserver" solution
>>> might be a good option.
>>>
>>> I simply mentioned that the end-user shouldn't be bothered with unwanted
>>> time-outs.
>>> Iow, if a session has a timeout, a new request must be able to produce
>>> the request.
>>>
>>> The login stuff, another issue, should never rely on a session object.
>>> If you need a time-out on a authentication, don't use the session but
>>> make sure the authentication itselfs has a time-out.
>>> It's a vision of mine not to use the session object in such a way the
>>> user get's bothered.
>>>
>>> When i access hotmail and i go to diner and come back i can continue,
>>> unless my cookie has expired, which is a month or so :)
>>>
>>>
>>>
>>>
>>>
>>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>>> news:%23%23ueqCmJGHA.1032@.TK2MSFTNGP11.phx.gbl...
>>>> I'm not sure what problem you have with Session State. It is there for
>>>> a purpose. "imo" is not a logical reason for doing or not doing
>>>> something. An opinion is a poor substitute for a fact. The fact that
>>>> Session times out makes it eminently suitable for any user-specific
>>>> temporary data storage that should expire within a given time span.
>>>> That is what it was designed for.
>>>>
>>>> --
>>>> HTH,
>>>>
>>>> Kevin Spencer
>>>> Microsoft MVP
>>>> .Net Developer
>>>> Who is Mighty Abbott?
>>>> A twin turret scalawag.
>>>>
>>>> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
>>>> news:43df229a$0$12846$ba620dc5@.text.nova.planet.nl ...
>>>>> But.. that's quiet the opposite to what i meant.
>>>>>
>>>>> I mean, you could use this 'trick' via a session but what i want is
>>>>> that the session is not used for kinds of stuff.
>>>>> The expiration of the authentication is not involved with the session
>>>>> so one actually should use the authentication stuff to reach his goal
>>>>> right?
>>>>>
>>>>> Expiration in a cookie can work the same as session expiring.
>>>>> Like i said, using the session and making the client depending on it
>>>>> is a bad approach imo.
>>>>>
>>>>>
>>>>>
>>>>>
>>>>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>>>>> news:%23EO4OMfJGHA.3936@.TK2MSFTNGP10.phx.gbl...
>>>>>>> Am i right on this?
>>>>>>
>>>>>> I would say yes. In fact, since you are wanting a timeout, Session is
>>>>>> actually the best solution for you.
>>>>>>
>>>>>> --
>>>>>> HTH,
>>>>>>
>>>>>> Kevin Spencer
>>>>>> Microsoft MVP
>>>>>> .Net Developer
>>>>>> Who is Mighty Abbott?
>>>>>> A twin turret scalawag.
>>>>>>
>>>>>>
>>>>>> "Edwin Knoppert" <info@.pbsoft.speedlinq.nl> wrote in message
>>>>>> news:drm3fp$d4a$1@.azure.qinip.net...
>>>>>>> I'll look into that tomorrow.
>>>>>>>
>>>>>>> I had a heavy discussion last week that colleagues of mine are
>>>>>>> misusing session variables.
>>>>>>> I don't want, if the session expires, the user get's bothered to log
>>>>>>> in again.
>>>>>>> I know, authentication is NOT session related, but my colleagues are
>>>>>>> misusing the session object to store a user id into.
>>>>>>> I have hard time to talk them into better use.
>>>>>>> If the session expires and your o so precious variable got lost,
>>>>>>> make sure you reload it and let the client continue with it's
>>>>>>> request.
>>>>>>>
>>>>>>> But.. i got warned that they don't want to keep authentication
>>>>>>> 'open' for a long period of time.
>>>>>>> I used to set a month ahead and the auto-expire-increase stuff
>>>>>>> (forgot) so the user was never bothered with a login again.
>>>>>>> But now they want to use a time-out and force a login.
>>>>>>> So i tested it today how it behavious.
>>>>>>> Fine by me, important to me is that they should understand the
>>>>>>> session stuff first.
>>>>>>>
>>>>>>> Am i right on this?
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in
>>>>>>> bericht news:%23%23$LofcJGHA.3064@.TK2MSFTNGP10.phx.gbl...
>>>>>>>> Why don't you use Session State? It behaves exactly the same
>>>>>>>> (except for timing out), and in fact, when it uses cookies, it uses
>>>>>>>> a non-persistent ("session") cookie to identify the client.
>>>>>>>>
>>>>>>>> More information: All you need to do to not persist a cookie is not
>>>>>>>> to set the Expiration property. This creates a session cookie on
>>>>>>>> the client, which is not stored in the file system, but in browser
>>>>>>>> memory. The difference between using a session cookie on the
>>>>>>>> client,and using Session State, is that Session State times out.
>>>>>>>> The client session cookie will remain on the client until the
>>>>>>>> domain is navigated away from, or the browser is closed.
>>>>>>>>
>>>>>>>> --
>>>>>>>> HTH,
>>>>>>>>
>>>>>>>> Kevin Spencer
>>>>>>>> Microsoft MVP
>>>>>>>> .Net Developer
>>>>>>>> Who is Mighty Abbott?
>>>>>>>> A twin turret scalawag.
>>
>>
Hehe :)

I might come back on this.

"Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
news:%23OyFEyqJGHA.2300@.TK2MSFTNGP15.phx.gbl...
>> Authentication ISNOT session... clear?
> Not really. That's sort of like saying that a chimney is not like a brick.
> But as long as *you're* clear, that's all that matters!
> --
> HTH,
> Kevin Spencer
> Microsoft MVP
> .Net Developer
> Who is Mighty Abbott?
> A twin turret scalawag.
> "Edwin Knoppert" <info@.pbsoft.speedlinq.nl> wrote in message
> news:drok2b$941$1@.azure.qinip.net...
>> Thanks,
>>
>> I'm do not entirly agree, in this case yes but if an app is critical,
>> like finacial/private or so, for myself i abandon my making use of
>> signoff() stuff.
>> Like i said, i was used to cookies set for a month, now i set it to
>> 15minutes and slidingexpiration.
>> So that 'could' be seen simialr to session expiring.
>> If you leave the computer and someone can start the browser and
>> continue.. well it's their choice to leave the browser unprotected.
>>
>> But now i think of it.. maybe the cookieless or similar stuff is the best
>> thing to do.
>> I have no experiance with that yet but i wouldn't see an odd session id
>> in my url..
>>
>> Still, to be persistant, i would not use the session to be the time-out,
>> it has nothing to do with authentication, maybe internally or indirect
>> but not for me as programmer.
>> If the admin chooses to increase or decrease session time-out i would not
>> want to be depending on that for the authentication matter.
>> Even so, if we would be 'superfriendly' we even could ask the client for
>> a authentication time-out.
>> yes, that would then require a cookie to be stored.. i know.
>>
>> Authentication ISNOT session... clear?
>> :)
>>
>>
>>
>>
>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>> news:uwaVoApJGHA.2708@.tk2msftngp13.phx.gbl...
>>> Hi Edwin,
>>>
>>> Perhaps I'm just misunderstanding your requirements. When you said "now
>>> they want to use a time-out and force a login" I understood you to mean
>>> that a literal timeout would be necessary. But when you say "When i
>>> access hotmail and i go to diner and come back i can continue, unless my
>>> cookie has expired, which is a month or so" I understand you to say that
>>> you do *not* need to use a timeout.
>>>
>>> Here's the crux of the issue: If you want to timeout the user during a
>>> browser session, Session State is the way to go. If you want to not
>>> require the user to log in for a month, a persistent cookie is the way
>>> to go. If you want the user to not time out, but to be logged out when
>>> he/sh closes the browser, a non-persistent (session) cookie is the way
>>> to go.
>>>
>>> Again, I don't understand what your requirements are. However, here are
>>> some security considerations to take into account when creating
>>> requirements.
>>>
>>> If you use anything but a server timeout (such as Session) you take a
>>> security risk. For example, if you use a session cookie, which does not
>>> expire as long as the browser remains opened, the user can leave, and
>>> another person can come and work on the same computer with that user's
>>> stuff. This is even worse if you set the expiration for some date in the
>>> future, as anyone that browses to the domain on that computer will be
>>> automatically logged in.
>>>
>>> --
>>> HTH,
>>>
>>> Kevin Spencer
>>> Microsoft MVP
>>> .Net Developer
>>> Who is Mighty Abbott?
>>> A twin turret scalawag.
>>>
>>>
>>> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
>>> news:43df5f39$0$1631$ba620dc5@.text.nova.planet.nl. ..
>>>> We have a miscommunication.
>>>> I agree on the session state, i read about it, the "sqlserver" solution
>>>> might be a good option.
>>>>
>>>> I simply mentioned that the end-user shouldn't be bothered with
>>>> unwanted time-outs.
>>>> Iow, if a session has a timeout, a new request must be able to produce
>>>> the request.
>>>>
>>>> The login stuff, another issue, should never rely on a session object.
>>>> If you need a time-out on a authentication, don't use the session but
>>>> make sure the authentication itselfs has a time-out.
>>>> It's a vision of mine not to use the session object in such a way the
>>>> user get's bothered.
>>>>
>>>> When i access hotmail and i go to diner and come back i can continue,
>>>> unless my cookie has expired, which is a month or so :)
>>>>
>>>>
>>>>
>>>>
>>>>
>>>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>>>> news:%23%23ueqCmJGHA.1032@.TK2MSFTNGP11.phx.gbl...
>>>>> I'm not sure what problem you have with Session State. It is there for
>>>>> a purpose. "imo" is not a logical reason for doing or not doing
>>>>> something. An opinion is a poor substitute for a fact. The fact that
>>>>> Session times out makes it eminently suitable for any user-specific
>>>>> temporary data storage that should expire within a given time span.
>>>>> That is what it was designed for.
>>>>>
>>>>> --
>>>>> HTH,
>>>>>
>>>>> Kevin Spencer
>>>>> Microsoft MVP
>>>>> .Net Developer
>>>>> Who is Mighty Abbott?
>>>>> A twin turret scalawag.
>>>>>
>>>>> "Edwin Knoppert" <news@.hellobasic.com> wrote in message
>>>>> news:43df229a$0$12846$ba620dc5@.text.nova.planet.nl ...
>>>>>> But.. that's quiet the opposite to what i meant.
>>>>>>
>>>>>> I mean, you could use this 'trick' via a session but what i want is
>>>>>> that the session is not used for kinds of stuff.
>>>>>> The expiration of the authentication is not involved with the session
>>>>>> so one actually should use the authentication stuff to reach his goal
>>>>>> right?
>>>>>>
>>>>>> Expiration in a cookie can work the same as session expiring.
>>>>>> Like i said, using the session and making the client depending on it
>>>>>> is a bad approach imo.
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in bericht
>>>>>> news:%23EO4OMfJGHA.3936@.TK2MSFTNGP10.phx.gbl...
>>>>>>>> Am i right on this?
>>>>>>>
>>>>>>> I would say yes. In fact, since you are wanting a timeout, Session
>>>>>>> is actually the best solution for you.
>>>>>>>
>>>>>>> --
>>>>>>> HTH,
>>>>>>>
>>>>>>> Kevin Spencer
>>>>>>> Microsoft MVP
>>>>>>> .Net Developer
>>>>>>> Who is Mighty Abbott?
>>>>>>> A twin turret scalawag.
>>>>>>>
>>>>>>>
>>>>>>> "Edwin Knoppert" <info@.pbsoft.speedlinq.nl> wrote in message
>>>>>>> news:drm3fp$d4a$1@.azure.qinip.net...
>>>>>>>> I'll look into that tomorrow.
>>>>>>>>
>>>>>>>> I had a heavy discussion last week that colleagues of mine are
>>>>>>>> misusing session variables.
>>>>>>>> I don't want, if the session expires, the user get's bothered to
>>>>>>>> log in again.
>>>>>>>> I know, authentication is NOT session related, but my colleagues
>>>>>>>> are misusing the session object to store a user id into.
>>>>>>>> I have hard time to talk them into better use.
>>>>>>>> If the session expires and your o so precious variable got lost,
>>>>>>>> make sure you reload it and let the client continue with it's
>>>>>>>> request.
>>>>>>>>
>>>>>>>> But.. i got warned that they don't want to keep authentication
>>>>>>>> 'open' for a long period of time.
>>>>>>>> I used to set a month ahead and the auto-expire-increase stuff
>>>>>>>> (forgot) so the user was never bothered with a login again.
>>>>>>>> But now they want to use a time-out and force a login.
>>>>>>>> So i tested it today how it behavious.
>>>>>>>> Fine by me, important to me is that they should understand the
>>>>>>>> session stuff first.
>>>>>>>>
>>>>>>>> Am i right on this?
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>> "Kevin Spencer" <kevin@.DIESPAMMERSDIEtakempis.com> schreef in
>>>>>>>> bericht news:%23%23$LofcJGHA.3064@.TK2MSFTNGP10.phx.gbl...
>>>>>>>>> Why don't you use Session State? It behaves exactly the same
>>>>>>>>> (except for timing out), and in fact, when it uses cookies, it
>>>>>>>>> uses a non-persistent ("session") cookie to identify the client.
>>>>>>>>>
>>>>>>>>> More information: All you need to do to not persist a cookie is
>>>>>>>>> not to set the Expiration property. This creates a session cookie
>>>>>>>>> on the client, which is not stored in the file system, but in
>>>>>>>>> browser memory. The difference between using a session cookie on
>>>>>>>>> the client,and using Session State, is that Session State times
>>>>>>>>> out. The client session cookie will remain on the client until the
>>>>>>>>> domain is navigated away from, or the browser is closed.
>>>>>>>>>
>>>>>>>>> --
>>>>>>>>> HTH,
>>>>>>>>>
>>>>>>>>> Kevin Spencer
>>>>>>>>> Microsoft MVP
>>>>>>>>> .Net Developer
>>>>>>>>> Who is Mighty Abbott?
>>>>>>>>> A twin turret scalawag.
>>>
>>>
>>
>>