Solved

Multiple authentication prompts over web

Posted on 2006-07-21
10
194 Views
Last Modified: 2013-12-18
Hi Experts:

Can you shed some light on this for me? I have a small web application (basically just a form) that users can access through the browser, fill in information and save again (nothing fancy, I know).

For security:

- I have created a role called [NonAnon] and added a readers and authors field to the form, each containing that role.

- Because this is a public app, I am using what we call a lightweight account in the address book (a person document, but no certificate -- authentication only on a password string).

- I've listed this account in the ACL and assigned it the [NonAnon] role, with Editor access.

- The form itself allows authors and above to create and read documents.

- Anonymous access in the ACL is set to None.

It all works fine (i.e. prompts to authenticate on accessing the document through the web). And the document goes into edit mode fine when the edit button is clicked. But when the save button is clicked, the document prompts to authenticate again, and then saves. Subsequent changes to the document do not require any reauthentication.

So basically each session requires two bouts of authentication -- one when first accessing the document, and one when first saving.

I would like only one authentication prompt when the user first accesses, though, with all saves not requiring reauthentication.

Any thoughts?

-Ke
0
Comment
Question by:kkiddie
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
10 Comments
 
LVL 46

Expert Comment

by:Sjef Bosman
ID: 17155953
Do you have logging enabled, e.g. domlog.nsf? Check whether in both cases the same URL was used, e.g. using
    http: //www.domain.com/filename.nsf/view/doc?OpenDocument
and
    http: //11.22.33.44/filename.nsf/view/doc?OpenDocument
might refer to the save server, but AFAIK the server considers it to come from a new user and will therefore require a new login.
   
0
 

Author Comment

by:kkiddie
ID: 17156226
They are logging with domlog.nsf, but for some reason today's traffic doesn't seem to be posted yet... I'll keep checking.

It's an good idea, but I don't think the URL is at issue.

I can tell you that the URL when accessing, (e.g. http: //www.domain.com/filename.nsf/view/doc?OpenDocument) is the same domain when the document goes into edit mode (e.g. http: //www.domain.com/filename.nsf/view/doc?EditDocument), and that the form method POST URL generated by Notes is a relative path and so should just be grabbing the domain from the address bar...
0
 
LVL 46

Expert Comment

by:Sjef Bosman
ID: 17157515
Ah, no, not always true. There are some Domino-generated URLs that are just plain wrong, despite the good intentions, although things have improved enormously since 4.6. If you use URLs yourself, they'll be correct, no doubt. Some URLs though, generated by agents and $$Return things could go terribly wrong. I hope that's corrected by now, but I can't tell because we used to generate ALL those URL's using one function, just to avoid URL changes.

Today's traffic? Try a view refresh with F9. Traffic should be in that database immediately. What Notes/Domino releases are you on?
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 46

Accepted Solution

by:
Sjef Bosman earned 125 total points
ID: 17157528
Some links that might come in handy:
    http:Q_20339652.html "Double Login to web application"
    http:Q_20397274.html "Double-authentication on web"
    http:Q_20380934.html "Help Required - Asking authentication twice in same application"
0
 
LVL 63

Assisted Solution

by:Zvonko
Zvonko earned 125 total points
ID: 17159421
Hello Ke,
isn't on the Form in Designer a property to default open the Document in Edit mode? Use that and you have solved two problems at once: no Button for Edit mode needed and only one authentication (for Edit) needed.

0
 
LVL 46

Expert Comment

by:Sjef Bosman
ID: 17159442
That's cheating!! ;-)
0
 
LVL 63

Expert Comment

by:Zvonko
ID: 17159477
Sorry, what? I do not get you? Or do you mean Zvonko reads what zvonko has written? There can be only One! :)
0
 
LVL 46

Expert Comment

by:Sjef Bosman
ID: 17159531
No, I meant putting the document in Edit mode is cheating. It doesn't solve the problem, it's just a bypass.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Lotus notes email code 2 131
Lotus Domino 9.0 install on same pc with 8.5.3 9 136
lotus domino server console error 1 86
Split Domain with Lotus Domino and Zimbra mail server. 5 268
For beginners of Lotus Notes user this is important to know about the types of files and their location supported by IBM Notes. Mostly users are unaware about how many file types are created and what their usages are. This Article is fully dedicated…
This article covers general Notes 8.5 troubleshooting information including recreating the Notes\Data folder.
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question