Ureader.com  
Microsoft software help and Community
   home   |   control panel login   |   archive   |  
 
DotNet
acad.assignment.mngr
academic
adonet
aspnet
aspnet.announcements
aspnet.build.controls
aspnet.caching
aspnet.datagridcontrol
aspnet.mobile
aspnet.security
aspnet.webcontrols
aspnet.webservices
clr
compactframework
component_services
datatools
distributed_apps
drawing
faqs
framework
framework.wmi
general
internationalization
interop
languages.csharp
languages.jscript
languages.vb
languages.vb.controls
languages.vb.data
languages.vb.upgrade
languages.vc
languages.vc.libraries
myservices
odbcnet
performance
remoting
scripting
sdk
security
setup
vjsharp
vsa
webservi.enhancements
webservices
windowsforms
windowsforms.controls
winforms.databinding
winforms.designtime
xml
  
 
date: Fri, 29 Feb 2008 19:56:55 -0800 (PST),    group: microsoft.public.dotnet.security        back       


iframes - security/cookies/session challenges   
If I told you a classic asp, or maybe asp.net website had a login page
with pages that were not accessible and until you logged in.. what
kind of security would you presume and how would cookies and session
data factor in that security model?

If I told you I needed to "somehow" introduce content under one of the
secured pages without modifying the site beyond introducing a link and
an iframe (which pointed to a asp.net 2.0 site page on another server)
what would be your expected concerns and obstacles?

I'm yet to try all this, but I did find this article:

http://petesbloggerama.blogspot.com/2007/08/aspnet-loss-of-session-cookies-with.html

My initial thought is the calling site will work fine, but how do I
secure the called page so that it can't be access except from the
secured calling site/page? Also, how can I instruct the calling page/
site that I'm all done and  least present a working go back button of
some sort.

Thanks for any help or information.
date: Fri, 29 Feb 2008 19:56:55 -0800 (PST)   author:   jc

Google
 
Web ureader.com


    COPYRIGHT 2007, YARDI TECHNOLOGY LIMITED, ALL RIGHT RESERVE  |   contact us