Securing your site with web.config
page 3 of 5
by . .
Average Rating: This article has not yet been rated.
Views (Total / Last 10 Days): 23298/ 55

Forms Authentication


Forms security works so that you don't have to create new Windows accounts to let people in. I won't go over how it works (see Security in ASP.NET). Here is the configuration -


<authentication mode="Forms">
<forms name="Auth" loginURL="login.aspx" protection="All" timeout="10" />


When you are authenticated you are given a cookie called 'Auth'. The place where you login is called login.aspx. The protection is by default - All, this gives the cookie validation (to make sure it hasn't been tampered) and encryption (using Triple-DES or DES), you can modify this with different properties (All, None, Encryption, Validation). Next the timeout sets when the user's login will time-out (the default in 30) in minutes.

Before we continue lets set up our login.aspx file -

<script language="VB" runat="server" />
Sub btn_click(sender as object, e as eventargs)
'You may want a database connection or something here
'To provide authentication from a database
If uname.Text = "philipq" And pword.text = "password" Then
FormsAuthentication.SetAuthCookie(uname.text, true)
lblmsg.Text = "Invalid username or password"
End If
End Sub

I'll leave you to put the server controls in.

All this does is check the values of the two textboxes (uname and pword) and if they're fine it sets Formsauthentication.SetAuthCookie() to validate the user. the SetAuthCookie method takes two parameters - the username of the authorized user and weather or not to keep the cookie after the user closes the browser. The FormsAuthentication provides many other useful methods.

So far we have given simple authentication for users and the data is automatically encrypted. The cookie is also encrypted like this -


You can clearly see the name of the cookie and the server it got it from.

View Entire Article

User Comments

Title: great   
Name: jhon
Date: 2004-09-09 3:51:04 AM
this is great!!!!!
Title: great   
Name: great
Date: 2004-09-09 3:50:17 AM
this is great!!!!!!11

Product Spotlight
Product Spotlight 

Community Advice: ASP | SQL | XML | Regular Expressions | Windows

©Copyright 1998-2021  |  Page Processed at 2021-03-01 5:15:10 AM  AspAlliance Recent Articles RSS Feed
About ASPAlliance | Newsgroups | Advertise | Authors | Email Lists | Feedback | Link To Us | Privacy | Search