CodeVerge.Net Beta


   Explore    Item Entry    Members      Register  Login  
NEWSGROUP
.NET
Algorithms-Data Structures
Asp.Net
C Plus Plus
CSharp
Database
HTML
Javascript
Linq
Other
Regular Expressions
VB.Net
XML

Free Download:




Zone: > NEWSGROUP > Asp.Net Forum > general_asp.net.security Tags:
Item Type: NewsGroup Date Entered: 10/28/2006 4:59:12 PM Date Modified: Subscribers: 0 Subscribe Alert
Rate It:
(NR, 0)
XPoints: N/A Replies: 2 Views: 8 Favorited: 0 Favorite
Can Reply:  No Members Can Edit: No Online: Yes
3 Items, 1 Pages 1 |< << Go >> >|
Mauro_net
Asp.Net User
Finding the perfect auth metod for Me :)10/28/2006 4:59:12 PM

0/0

Hi Fellows, maybe some of you can help me solve this issue I cannot find workaround for (I've googled it up, trust me)

I need to implement security on my apps, with the following requirements:

- Login / logged in blocks must be inside a usercontrol, mainly cause I need to place it on different places on different pages
- I have a public area, that is, even not authenticated users have something to mess with.
- I need roles, and according to these roles, render the pages/ controls in different ways (for instance, if you're admin, you can delete stuff, if you're not, you can se stuff but deleting is disabled, but the container control is the same)
- I don't want to use the membership controls since that uses its own database, and that does not work for me, for i need to implement (for instance) referential integrity, so if user is deleted.... delete all the stuff he's guilty for. I also need my own control so I can squeeze it the way i like :)
- I need to be able to retrieve account's data at any time (for logging user's actions)

As an 'old' asp programmer, maybe I'm looking at this with old fashion glasses, but I think forms-auth is the way to go. What would u suggest? I cannot find an example where that thing is inside a usercontrol and afterwards using account's details to ensure conditional control over pages.

Help!
And thanks 2 u all in advance,
Mauro

DLester01
Asp.Net User
Re: Finding the perfect auth metod for Me :)10/31/2006 9:35:29 PM

0/0

As long as you specify a connection string for the membership provider it doesn't care which database it resides in.  I think that the membership is the best way forward and you can put the login controls within your own controls.

If the membership database design is not to your liking then you could always create your own membership/role providers.

 

Regards.

Mauro_net
Asp.Net User
Re: Finding the perfect auth metod for Me :)10/31/2006 11:41:14 PM

0/0

Ok, I've read the complete chapter about "membership" from a book I had. DLester01, I kept in mind what u said all the time and it was pretty useful, it might be my 'way to go'

Now my question is... suppose I DO have time to build my own set of login/auth controls and manage all the users and roles myself (which i did for old asp and works just fine) ... is still any other reason why I would want to use this membership stuff?
The way i see it, you just need a few 'modules' where to login and some others for user administration... and you can have 100% control over the controls, fields, extended properties, whatever u want to add it!

What makes the membership control-set so good? Why is it called API if it's nothing more than a bunch of controls doing the 'dirty' ado.net stuff for you? Is there any special security feature? Is there an extremelly complex flow? How is the session info stored? It's scary for me the idea of modifying cusomer's needs just because there's something out there already done which partly does the job.

 I say all this because I really need to understand it very well if I'm gona jump into a "prebuilt world" (aka asp.net)
Most people will say "we dont like your complain" but i really need to understand how from one day to another, everybody likes it this way.

I feel much better now :)
Regards,
Mauro

3 Items, 1 Pages 1 |< << Go >> >|


Free Download:

Books:
Finding Your Voice: How to Put Personality in Your Writing Authors: Leslie Edgerton, Pages: 241, Published: 2003

Web:
Judi Perkins, How To Find The Perfect Job - Vault Blogs The result is that the hiring authority is puzzled as to how you managed to ..... seekers how find their perfect job through renegade methods that entail ...
How to find the perfect date | eHow.com How to find the perfect date. Well here it is, a big event vastly approaching and you find you have no date! Follow my handy dandy methods and you will find ...
Method for Finding Scientific Truth Sometimes the testimony is based on authority, as would be the case if an Olympic gold medalist told me about Bogus Basin. Many religions claim that ...
You Had Me At EHLO... : How to Configure Certificate Based ... Select the User one or more standard authentication methods: radio check box. .... It would be a perfect world if Outlook and OCS could support SC logons ...
Finding the Perfect Real Estate Agent Finding the Perfect Real Estate Agent. There’s very little that’s more discouraging .... What can you tell me about the current real estate trends in my ...
Legal Resume Consultant, Legal Job Search, Sample Attorney Resume ... Legal Authority's method of direct marketing to hiring directors at ... Legal Authority more than doubles your chances of finding the perfect legal job. ...
Amazon.com: Perfect Passwords: Selection, Protection ... Perfect Passwords: Selection, Protection, Authentication [ILLUSTRATED] ( Paperback) ..... are usually chosen, and why most of those methods are really bad. ...
MySql >= 4.1 Client does not support authentication protocol... This was perfect, id tried other methods of making the auth. backward compatible which didnt help, this saved me MUCH time :). Comment Saturday, March 19, ...
Ipseccmd The PFS parameter is optional, and it enables session key perfect forward ... If you omit the -a parameter, the default authentication method is Kerberos. ...
Perfect Paper Passwords and SSH on Linux at Code|Beta The first step is to download the source code and if you’re like me and .... Now to activate this authentication method you would simply add the line: ...

Videos:
The Demon-Haunted World: Science as a Candle in the Dark This is Carl's last interveiw (1996) Full interview: Part1 http://www.youtube.com/watch?v=GU192A1Oz4k Part2 http://www.youtube.com/watch?v=Mzd9vFLQQ...
Zeitgeist, The Movie | Final Edition [ ENGLISH subtitles ] Zeitgeist, The Movie | Final Edition [ ENGLISH subtitles ]
Why Are Americans So Angry? HON. RON PAUL OF TEXAS Before the U.S. House of Representatives | June 29, 2006
Opencast Project Open House at UC Berkeley http://www.opencastproject.org/ Opencast is an initiative driven by higher education institutions to empower: institutions - to make informed choic...
A New Way to look at Networking Google Tech Talks August 30, 2006 Van Jacobson is a Research Fellow at PARC. Prior to that he was Chief Scientist and co-founder of Packet Design. P...
김동완 앨범 촬영 영상
Charlie Rose - An hour with Larry Summers A conversation with Harvard University President Larry Summers. He steps down from that position on June 30th. He discusses his time at the univers...
Toward the First Revolution in the Mind Sciences Google TechTalks August 8, 2006 B. Alan Wallace, Ph.D. has been a scholar and practitioner of Buddhism since 1970. He is currently seeking ways to i...
Charlie Rose - Michael Chertoff; James Risen. Segment 1: Michael Chertoff, Secretary of Homeland Security, talks about threats facing the United States and the government's response. Segment 2: J...
Charlie Rose - Sidney Lumet / Preview of Eugene O'Neill documentary Segment 1: Filmmaker Sidney Lumet talks about his career in film. His films include "12 Angry Men", "Network", and "Serpico". His latest is "Find ...




Search This Site:










vs2008 standard edition and windows mobile

html/text module

htmlfeed problem

default button doesn't work on masterpage

windows auth .. getting locked out ???

referral anaylzer

building menus dynamically

problem migrating from vs2003 to vs 2005: _header.ascx exists in both .....

phishing website??

mysql provider code needed - how do i add mysql as a provider within the asp.netwebadmin tool?

has anyone integrated a rich text box into the admin area?

absolutly new to asp- my first login page

treeview onselectedindexchange client side event question

cannot connect to oracle database when using wap

thoughts on virtual dns servers

returning custom datagriditem from datagrid

login message display with visible tab

forms authenication and client browsers

3.0.13: log viewer error

controls disappear: masterpage, linkbutton & sitemappath debugging

cross-portal data browsing

adding a textbox with treeview control

what to open url and make button visible

security password on manipulating data

remote debugging through remote iis?

dnn 4 logging users out prematurally.

iis error “aspnetdb.mdf is read-only” but it is not set to read only?

soap trace microsoft tool kit

why doesn't the 'modules' table delete any entries?

help contribute for a macmini to support dotnetnuke testing

 
All Times Are GMT