forms authentication with framesets

From: Andy Fish (ajfish_at_blueyonder.co.uk)
Date: 06/12/04


Date: Sat, 12 Jun 2004 11:46:36 GMT

Hi,

I have a problem using forms based authentication with a frameset.

I made sure the containing frameset is an aspx so the first time the user
tries to access the application he just gets the login page, and the
frameset doesn't appear until after he's logged in

However, when the user's login session times out and he subsequently tries
to work in one of the frames (i.e. clicks a link). that individual frame
redirects to the login screen. This is OK if he's in the "main" pane but
looks silly if he has clicked on the narrow "menu" frame on the left hand
side.

What I want is for the whole frameset to clear and be replaced by the login
screen.

I can see that the solution would have to be client-side (which is why I
suspect the problem is not specific to forms authentication) but I'm stuck
for a workable option.

Anyone got any ideas of how to do this? How about it I abandon forms
authentication and roll my own authentication - is it possible then?

Thanks for your help

Andy



Relevant Pages

  • Security Access for external users
    ... a user logs in for the first time that day thru ... last login instead of the latest actual login. ... Integrated Windows authentication. ...
    (microsoft.public.inetserver.iis.security)
  • Re: forms authentication with framesets
    ... out of frame" in the login.aspx page ... > I have a problem using forms based authentication with a frameset. ... when the user's login session times out and he subsequently tries ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Testing with FormsAuthentication
    ... > I'm am testing a login page with Forms Authentication. ... When I've> logged in the first time then subsequent tests do not go baack to the ... > login page because it finds the necessary cookie in memory. ...
    (microsoft.public.dotnet.framework.aspnet)
  • [Full-Disclosure] Advisory: Dark Age of Camelot - Weak encryption of network traffic exposed persona
    ... Weak encryption in game client exposed customer billing and authentication ... encryption for billing information. ... The login binary has undergone several updates since then. ...
    (Full-Disclosure)
  • Re: [PHP] Is this the best way?
    ... Why is Jason schreefing again? ... maybe I should edit my authentication function... ... attempting to login. ... really be either attempting an authentication *or* outputting some ...
    (php.general)