Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDevelopment and...Development and...Building ExtensionsBuilding ExtensionsOther Extension...Other Extension...Potencial DnnApiController security bugPotencial DnnApiController security bug
Previous
 
Next
New Post
5/27/2014 1:24 PM
 

Some time ago I developed a Dnn Web Api Service (DnnApiController descendant) which is consumed by a standard desktop application using the HttpClient .Net class. 

For security measures, all the service methods must require authentication. This has worked fine until I changed (again for security measures) the webconfig parameter enablePasswordRetrieval="false". Since then, I can no longer call any methods of the services. 

I get the following error:


{StatusCode: 500, ReasonPhrase: 'Internal Server Error', Version: 1.1, Content: System.Net.Http.StreamContent, Headers:

{

  Cache-Control: private

  Date: Tue, 27 May 2014 17:08:15 GMT

  Server: Microsoft-IIS/7.5

  X-AspNet-Version: 4.0.30319

  X-Powered-By: ASP.NET

  Content-Length: 3640

  Content-Type: text/html; charset=utf-8

}}

 

In order to get this working again, I must to go back and enablePasswordRetrieval or allow anonymous call to the methods. Any of them are the ideal solution.

Has someone experience the same situation?

Greetings...
 
New Post
5/28/2014 3:19 AM
 
its fine to set enablePasswordRetrieval to true - since 7.1.0 DNN does not send out passwords (only password reset links) so no secure information is leaked (such as a password in a cleartext email). If you log this to support.dnnsoftware.com we can look into it and see if we can resolve it (I suspect it is a piece of spurious logic around hashed passwords). Please also reference this thread and let us know what passwordFormat you use in web.config

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
Previous
 
Next
HomeHomeDevelopment and...Development and...Building ExtensionsBuilding ExtensionsOther Extension...Other Extension...Potencial DnnApiController security bugPotencial DnnApiController security bug


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out