Force reauthentication with basic auth on IIS?

Discussion in 'Java' started by JGH, Feb 7, 2005.

  1. JGH

    JGH Guest

    I am trying to write a web page that features a "logoff" button on a site
    that uses basic authentication on an IIS server.

    In php, there is a way to send a header to tell the browser it needs to
    authenticate. Can I also do that in jsp/java?
    JGH, Feb 7, 2005
    #1
    1. Advertising

  2. JGH

    Guest

    The way basic authentication work, your password is sent to the server.
    Since http is stateless, with basic authentication (as opposed to
    digest authentication), user name and password are sent every time you
    make a request. The reason you dont get asked to type in password
    every two seconds is because the browser stores your credentials for
    you. If you want to get it to prompt for username/password again,
    browser has to be told that authentication failed with whatever
    credentials it has stored in the security realm. The way to do this is
    to send a 401 Authentication Required response. Basically, if you can
    figure out on the server side when you need the user to reauthenticate,
    just create a 401 response and send it back instead of whatever you'd
    normally send.

    Hope this helps,
    Anton
    , Feb 9, 2005
    #2
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. =?Utf-8?B?Q2hyaXMgTW9oYW4=?=

    Configuring Windows Auth & Forms Auth in Asp.Net

    =?Utf-8?B?Q2hyaXMgTW9oYW4=?=, Apr 28, 2004, in forum: ASP .Net
    Replies:
    0
    Views:
    673
    =?Utf-8?B?Q2hyaXMgTW9oYW4=?=
    Apr 28, 2004
  2. =?Utf-8?B?ZGhucml2ZXJzaWRl?=

    Windows Auth, but Forms Auth for one page?

    =?Utf-8?B?ZGhucml2ZXJzaWRl?=, Jan 8, 2005, in forum: ASP .Net
    Replies:
    1
    Views:
    521
    Elton Wang
    Jan 8, 2005
  3. Mark Chai
    Replies:
    1
    Views:
    729
    Christophe Vanfleteren
    Oct 1, 2003
  4. Alek Davis
    Replies:
    0
    Views:
    352
    Alek Davis
    Oct 24, 2003
  5. Andrew_Revinsky

    Forcing Reauthentication for a Webform with NTLM auth..ion

    Andrew_Revinsky, Jul 9, 2004, in forum: ASP .Net Security
    Replies:
    3
    Views:
    261
    Ian Ringrose
    Jul 14, 2004
Loading...

Share This Page