List Info

Thread: Multiple Login Pages?




Multiple Login Pages?
user name
2006-04-13 14:35:32
Why? I can't imagine it ever to be preferable to have a
different login
for a different role, since it will inevitably lead to
code-duplication
and an increased vulnerability to 'bad people'.

-----Original Message-----
From: Discussion of building .NET applications targeted for
the Web
[mailtoOTNET-WE
BDISCUSS.DEVELOP.COM] On Behalf Of Brian Vallelunga
Sent: Thursday, April 13, 2006 16:27
To: DOTNET-WEBDISCUSS.DEVELOP.COM
Subject: Re: [DOTNET-WEB] Multiple Login Pages?

Sure, I'm aware of that, but there's no sensitive
information given out.
In my case I'm using email and password for both groups of
people, but
imagine that customers use email and password and admins use
an employee
id and password. This is the exact situation where it would
be
preferable to have two login pages.

-----Original Message-----
From: Discussion of building .NET applications targeted for
the Web
[mailtoOTNET-WE
BDISCUSS.DEVELOP.COM] On Behalf Of Ryan Heath
Sent: Thursday, April 13, 2006 2:27 AM
To: DOTNET-WEBDISCUSS.DEVELOP.COM
Subject: Re: [DOTNET-WEB] Multiple Login Pages?

On 4/12/06, Brian Vallelunga <brianvallelunga.com> wrote:
>
> As a workaround, I put the login logic and controls for
each group 
> into separate user controls and have just one sign-in
page. On page 
> load, I check where the user is trying to go (custom or
admin area), 
> via the ReturnUrl value and serve up the correct user
control.
>

You know that customers can request the login page in
"an admin state",
dont you?
To me it seems little value to, *before* the user is
authenticated, give
him/her specific information about his/her role *when* s/he
is
authenticated ...

// Ryan

===================================
This list is hosted by DevelopMentor(r)  http://www.develop.com

View archives and manage your subscription(s) at
http://discuss.develop.com


===================================
This list is hosted by DevelopMentor(r)  http://www.develop.com

View archives and manage your subscription(s) at
http://discuss.develop.com


===================================
This list is hosted by DevelopMentorŪ  http://www.develop.com

View archives and manage your subscription(s) at http://discuss.develop.com

[1]

about | contact  Other archives ( Real Estate discussion Medical topics )