Beginner Programming
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOtherBeginner Programming

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stay one step ahead of the competition. Evaluate and give feedback on some of the hottest web development tools on the market today. Make your opinion heard! Click Here
  #1  
Old November 19th, 2001, 09:31 AM
Joellyn Joellyn is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2001
Posts: 2 Joellyn User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Question Securing a directory

I would like part of a website I'm developing to only be accessible by a certain group of people. All 20-25 people could have the same username and password...

My first thought would be to set up a new user and a directory on the website with special permissions (I know nothing about how to do it, mind you) so when someone tried to access a page in this directory, they'd be asked to supply a username and password (authenticate?) We're running IIS 5.0.

Our tech guy seemed to think using cookies would be a better way to go.

What's the best way to go about this? Thanks

Reply With Quote
  #2  
Old November 19th, 2001, 01:25 PM
lucasalexander lucasalexander is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2001
Location: Atlanta
Posts: 39 lucasalexander User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 8
Send a message via AIM to lucasalexander Send a message via MSN to lucasalexander
If you want to go the cookie route, you'll need to make sure all the pages in the directory can read cookies and redirect the user if the cookie isn't set. So, all your pages would need to be ASP/PHP etc. If this is the case, all you need to do is have users enter name/password on a page and then set a session variable on login.

However, setting the directory permissions through IIS would probably be just as easy, especially if everyone is going to use the same login information.
__________________
Lucas Alexander
http://www.alexanderdevelopment.net

Reply With Quote
  #3  
Old November 19th, 2001, 02:32 PM
AlCapone's Avatar
AlCapone AlCapone is offline
Mobbing Gangster
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Sep 2001
Location: "Best City" 2002 and 2003- Melbourne, Australia
Posts: 4,913 AlCapone User rank is Sergeant (500 - 2000 Reputation Level)AlCapone User rank is Sergeant (500 - 2000 Reputation Level)AlCapone User rank is Sergeant (500 - 2000 Reputation Level)AlCapone User rank is Sergeant (500 - 2000 Reputation Level)AlCapone User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 5 h 36 m 31 sec
Reputation Power: 17
Send a message via ICQ to AlCapone Send a message via AIM to AlCapone Send a message via Yahoo to AlCapone
the best solutions (of course ) would be to install apache and use .htaccess for that and many more purposes
And IMO, cookies are not reliable and should be avoided whenever possible
__________________
And you know I mean that.

Reply With Quote
  #4  
Old November 21st, 2001, 12:50 PM
Joellyn Joellyn is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2001
Posts: 2 Joellyn User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Thanks....

...for your insight. I'm really hesitant to use cookies - just seems like quite a pain.

Could anyone provide me with some insight on this IIS Authentication? Found a good article on iisadministrator.com, but wondered if any of you have more experience with actually setting this up.

Reply With Quote
  #5  
Old November 27th, 2001, 03:28 PM
Fjodor Fjodor is offline
Slacker
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2001
Location: Sweden
Posts: 76 Fjodor User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 8
Cookies are a good tool to use for alot of things, but htaccess has the advantage of working eventhough the user might have cookies turned off.

/Fjodor

Reply With Quote
Reply

Viewing: Dev Shed ForumsOtherBeginner Programming > Securing a directory


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 2 hosted by Hostway