an ASP.NET Open Source CMS & eCommerce platform
Search:
Last Post 11/1/2010 10:08:33 AM By Bahram. 9 replies.
10/26/2010 2:13:36 PM
Bahram
Posts: 878
Joined: 12/8/2008
Location:Vancouver, BC Canada
Login Session Cookies
 Hi Luke,
 
Does DSC uses session cookies for user's Login, If yes can we use it for other programs to use them for auto-login?
 
Bahram
10/26/2010 2:53:31 PM
lukezy
Posts: 2109
Joined: 6/12/2007
Location:WA, US
Re: Login Session Cookies
It's configured in web.config. The default web.config is using cookie. You don't want to use DSC cookie for other apps. Each app should have its own login.
DotShoppingCart Staff
10/27/2010 9:32:42 AM
Bahram
Posts: 878
Joined: 12/8/2008
Location:Vancouver, BC Canada
Re: Login Session Cookies
 Sure, we use another cookie. Is there a Function or SP to get password by username or email.
 
10/27/2010 9:34:47 AM
lukezy
Posts: 2109
Joined: 6/12/2007
Location:WA, US
Re: Login Session Cookies
No, password is never stored.
DotShoppingCart Staff
10/27/2010 9:39:19 AM
Bahram
Posts: 878
Joined: 12/8/2008
Location:Vancouver, BC Canada
Re: Login Session Cookies
 So How can I auto Login using data of a cookie which is only email or user name?
10/27/2010 9:52:17 AM
Bahram
Posts: 878
Joined: 12/8/2008
Location:Vancouver, BC Canada
Re: Login Session Cookies
 You mean password never stored in cookie? Yes It is true. and I will read email from cookie to get Password and do auto login
 
 
10/27/2010 9:55:03 AM
lukezy
Posts: 2109
Joined: 6/12/2007
Location:WA, US
Re: Login Session Cookies
Pasword is never stored anywhere. I am not sure what you are trying to accomplish.
DotShoppingCart Staff
10/27/2010 10:09:24 AM
Bahram
Posts: 878
Joined: 12/8/2008
Location:Vancouver, BC Canada
Re: Login Session Cookies
 I am creating a cookie for a Single Sign On system. so when users login to a website, and then they browse to our store, they are auto-Logged in (by my custom code using cookie data) and do not have to enter username and password.  
 
Menawhile I see aspnet_membership table has a field called password.
10/28/2010 10:03:29 AM
lukezy
Posts: 2109
Joined: 6/12/2007
Location:WA, US
Re: Login Session Cookies
You can use FormsAuthentication.SetAuthCookie(username, true)  to make it logged in without validating the password. However you need to understand what you are doing and avoid any security holes.
DotShoppingCart Staff
11/1/2010 10:08:33 AM
Bahram
Posts: 878
Joined: 12/8/2008
Location:Vancouver, BC Canada
Re: Login Session Cookies
Hi Luke,
 
 I am using false parameter to create a cookie, for future auto logins, I have two question :
 
1- What is current expiry time for DSC logins
2-When a Url (i.e a product page) in DSC site is called, then what ASP code in site is always executed first?
 
I am looking for a place in site structure to read a cookie to login. It does not guarantee that users always type default URL, but may type any aspx page of store.
 
Thanks,