Solved

ASP Classic and Basic Authentication

Posted on 2010-08-27
2
881 Views
Last Modified: 2012-05-10
I have an ASP Classic web site that is running on an IIS that is setup for Basic Authentication with anonymous access disabled.  I also have a login script that requires the user to type in a username and then validates it across active directory for their password, once validated it then creates several cookies to be used throughout the site.

Right now when you navigate to the site for the first time, you have to login to the windows authentication prompt, then login again at my login page.  Is there a way to capture the basic authentication username and password and have it pass to the login I already have?

I have included some of the code that I am using for the login validation page.
'**************************
'Active Directory CheckSum
'**************************	
On Error Resume Next	
if (not strUserName= "") then
		
	strADsPath = "WinNT://" & strADsPath
	Dim oADsObject  
	Dim tempstr
	tempstr = strDomain & "\" & strUserName
	
	Set oADsObject = GetObject(strADsPath)
	
	Dim strADsNamespace
	Dim oADsNamespace
	strADsNamespace = left(strADsPath, instr(strADsPath, ":"))
	set oADsNamespace = GetObject(strADsNamespace)
	Set oADsObject = oADsNamespace.OpenDSObject(strADsPath, tempstr, strPassword, 0)
	
	if not (Err.number = 0) then				
		Response.redirect"login.asp?Message=Please provide a correct login name<br>or system password for the " & strDomain & " domain!<br>"
		'response.write err.description & "<p>"
		if err.number = -2147022987 then ' for account logout
			Response.write "<strong>Your account has been logged out!</strong>"
		end if
		
	else				
		Dim strProj, Objrs
		Set Objrs = Server.CreateObject("ADODB.Recordset")
		Call OPEN_DB
		If AreYouATech = 1 Then
			strProj = "SELECT * FROM tblTechnician Where username = '" & StrUserName & "'"
		Else
			strProj = "SELECT * FROM tblNonTechnician WHERE ClientEmplID = " & StrUserName
		End If
		Set Objrs = MyConn.Execute(strProj)
		
		If NOT Objrs.EOF Then
			If AreYouATech = 1 Then
				'Cookies Go Here
			Else
				Dim RSClient, SQLClient
				Set RSClient = Server.CreateObject("ADODB.Recordset")
				Call OPEN_DB
				SQLClient = "SELECT * FROM tblClient WHERE ClientEmplID = " & StrUserName
				Set RSClient = MyConn.Execute(SQLClient)
				
				'Cookies Go Here
			End If
		Else
			Set Objrs = Nothing
			Set ObjConn = Nothing
			Response.redirect"login.asp?Message=Invalid UserName! Please try again"
		End If
	End If
End If

Open in new window

0
Comment
Question by:LouSch7
  • 2
2 Comments
 
LVL 14

Expert Comment

by:wolfman007
ID: 33542940
Request.ServerVariables("LOGON_USER") will pick up the username for the user when you are using Basic Authentication

see the following website

Authentication Methods in IIS
http://www.4guysfromrolla.com/webtech/020201-1.shtml
Request.ServerVariables("LOGON_USER")

Open in new window

0
 
LVL 14

Accepted Solution

by:
wolfman007 earned 500 total points
ID: 33542995
You could also try using

Request.ServerVariables("AUTH_USER") Returns the raw authenticated user name

Request.ServerVariables("AUTH_PASSWORD") Returns the value entered in the client's authentication dialog

ASP ServerVariables Collection
http://www.w3schools.com/asp/coll_servervariables.asp
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I have helped a lot of people on EE with their coding sources and have enjoyed near about every minute of it. Sometimes it can get a little tedious but it is always a challenge and the one thing that I always say is:  The Exchange of information …
Running classic asp applications under Windows Server 2008 R2 (x64) and IIS 7 is not as easy as one may think. It took me a while to figure it out while getting error 8002801d a few times. After you install the OS you will need to install the fol…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question