Re: ASP Session, Cookies and SSL
From: Andrew Zamkovoy (zam_at_parks.lv)
Date: 09/26/04
- Previous message: Bob Barrows [MVP]: "Re: ASP Session, Cookies and SSL"
- In reply to: Adil Akram: "ASP Session, Cookies and SSL"
- Next in thread: Adil Akram: "Re: ASP Session, Cookies and SSL"
- Reply: Adil Akram: "Re: ASP Session, Cookies and SSL"
- Messages sorted by: [ date ] [ thread ]
Date: Sun, 26 Sep 2004 16:11:24 +0300
Hello,
Leave all products pages under HTTP connection (good for Search Engine).
Keep "Shopping Cart" (SessionID, ProductID, SubProductID, Qty) in database
(let it be table: BASKET) (not in cookies).
When is time for checkout do redirect on HTTPS checkout pages:
Response.Redirect
("https://checkout.domain.com?ShopID=<%=Application("MyShopGlobalID")%>&Orde
rSession=<%=Session.SessionID%>")
P.S. ?ShopID=<%=Application("MyShopGlobalID")%>& if you have multiply shops.
After checkout (success and unsucess) on HTTPS side complete, make direction
back on HTTP web site...
With best regards,
-- Should you have any questions, please don't hesitate to contact me. If you response to an email, please quote the complete message. http://1click.lv "Adil Akram" <microsoftee@informit.com.pk> wrote in message news:eYeKoI7oEHA.536@TK2MSFTNGP11.phx.gbl... > I have created a site shopping cart in ASP.net. > > I am using ASP session object's SessionID on non SSL connection to track > session. > While adding products to cart DB I insert product and SessionID in table. > All products and cart status pages are on non SSL connection. > > On checkout to get secure user information I shifted connection to SSL but > when shifting to SSL, the SessionID changed (As is this is default behavior > of IIS to prevent stealing SSL session). > > To get rid of this problem I shifted my all products and cart pages to SSL, > now its working fine but I am not satisfied with this solution because it is > not feasible to put all product pages (about 500 pages) to SSL. As I see > while shopping with big companies sites i.e. Microsoft, Amazon etc. they > change to SSL only in checkout page. > > How can I build it like that all pages remains in non SSL and only checkout > pages should be on SSL. One solution may be to use custom cookies to track > session but it may have the same problem of session hijacking/ session > stealing. > > Any one please explain me what is the best way to create shopping cart with > SSL, the ASP/ASP.net session or setting own cookies. > > Please explain in detail or refer some useful links. > > regards, > Adil > > > >
- Previous message: Bob Barrows [MVP]: "Re: ASP Session, Cookies and SSL"
- In reply to: Adil Akram: "ASP Session, Cookies and SSL"
- Next in thread: Adil Akram: "Re: ASP Session, Cookies and SSL"
- Reply: Adil Akram: "Re: ASP Session, Cookies and SSL"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|