In order for this mixed model authentication scenario to work, and also to make it easy on developers, a common and familiar security model is required for authentication, and subsequently authorisation. If we were trying to...
See more »
In order for this mixed model authentication scenario to work, and also to make it easy on developers, a common and familiar security model is required for authentication, and subsequently authorisation. If we were trying to emulate windows integrated authentication from a forms authentication based site, it would be extremely difficult, if not impossible to accurately mimic, and obtain a users roles from the domain in a seamless manner. It would be much easier to let windows/IIS provide a users roles for us in an appropriate principal object, and to extract those roles, and mimic a forms authentication process. This method means that to the application, all users have authenticated via the forms authentication method, but that intranet users will have a larger and more specific set of roles attached with their principal object. The diagram below illustrates this.
See less »
Kaboodle will send you a newsletter and updates from your friends. You can unsubscribe at any time. Kaboodle does not sell or share your email address or personal information with anyone.
Kaboodle requires all users to provide their real date of birth as both a safety precaution and as a means
of preserving the integrity of the site. You will be able to hide this information from your profile if you wish.
Added by 1 people