Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsIFrameIFrameDoes it secure to pass User ID in querystring?Does it secure to pass User ID in querystring?
Previous
 
Next
New Post
11/5/2007 9:28 PM
 

Hi everyone,

   I am trying to use DNN user profile to login other application through the IFrame, but I think pass UserID using IFrame parameter isn't secure. does anyone have more secure way to achive it?

 

Dan

 
New Post
11/6/2007 9:19 AM
 

Passing UserId isn't going to compromise anything. First of all it's exposed in other areas of DNN (granted, not to everybody). Second, it's no more dangerous then passing a username. IMHO.


Vitaly Kozadayev
Principal
Viva Portals, L.L.C.
 
New Post
11/6/2007 6:41 PM
 

Hi Vitaly,

Thanks a lot for your anwser, I may have to pass the UserName beacuse UserID doesn't mean any thing for other application, my project manager refuse to use querystring. he recommand to use expired cookies, all the application are setting under same domain.

I perfer to pass the value through the IFRame,because it doesn't modify the DNN application. what do you advice? thanks in advance.

 

Dan

 
New Post
11/7/2007 2:06 AM
 

I modified IFrame for a customer, it made a webservice call to the server behind for authentification. As a result, a security token was submitted which was afterwards used as querystring parameter. Thhesecurity tokens  life time was limited to life only few minutes.

Even If this worked, I advise everybody not using Iframes for any security related applications. 

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsIFrameIFrameDoes it secure to pass User ID in querystring?Does it secure to pass User ID in querystring?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out