Re: Passing custom headers to login page

Adam Tuliper <[email protected]>
Newsgroups gmane.comp.windows.devel.dotnet.advanced
Message-ID <[email protected]>
there is a roll your own type out there requiring a third server (er.. site
since you could use your own server for two purposes of course)

http://aspalliance.com/1513_Cross_Site_Authentication_and_Data_Transfer.2




On Fri, Oct 10, 2008 at 10:27 AM, Geoff Taylor <[email protected]>wrote:

> Another option would be to do it something like the way Passport / Live
> Login works.  I've never really delved into it, but I suspect in your case
> it could work something like this:
>
> * On ClientServer, you need to authenticate.
> * The browser is redirected to the AuthenticatingServer, with a return URL
> in the querystring.
> * The AuthenticatingServer does some authentication (forms login, in your
> case).  Once successful, it redirects to the return URL, with a GUID token
> in the querystring.
> * The ClientServer receives this redirect, takes the GUID token, and makes
> a
> call to the AuthenticatingServer to request the user details (username
> etc.)
> * The ClientServer then has all the user details it needs, but the
> authentication is handled by the AuthenticatingServer, and the ClientServer
> never sees the user's password etc.
>
> The tricky bit is where the ClientServer retrieves the user details.  There
> are a bunch of ways this can be done (SOAP, XML web services, XML-RPC,
> REST,
> etc.), but you might be better just wrapping this bit up in a DLL and
> giving
> it to whoever runs the ClientServer.
>
> Good luck,
>
>                        Geoff
>
> > -----Original Message-----
> > From: Discussion of advanced .NET topics. [mailto:ADVANCED-
> > [email protected]] On Behalf Of Mont Rothstein
> > Sent: 10 October 2008 18:02
> > To: [email protected]
> > Subject: Re: [ADVANCED-DOTNET] Passing custom headers to login page
> >
> > Adam, thanks, you have been a huge help.
> > The FormsAuthentication methods were what I was missing.
> >
> > Re-writing the response to be an auto-submitting page didn't work
> > because
> > ASP.NET was po'd that the view state wasn't there.
> >
> > My custom header idea seems to be a no-go because there is no way to
> > add
> > custom headers to a re-directed response.
> >
> > That seems to leave me with having to pass the username and password in
> > the
> > query string.
> >
> > Do you see any other option (other than not doing this cross-site
> > autologin
> > at all :-) ?
> >
> > Thanks again,
> > -Mont
> >
> > ===================================
> > View archives and manage your subscription(s) at
> > http://peach.ease.lsoft.com/archives
>
> ===================================
> View archives and manage your subscription(s) at
> http://peach.ease.lsoft.com/archives
>

===================================
View archives and manage your subscription(s) at http://peach.ease.lsoft.com/archives
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.