Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

DotNetNuke Marketplace
  Ads  
Aspose - The .NET & Java component publisher
 


  Sponsors  

Meet Our Sponsors

Portal Webhosting - Hosting For Developers
Red-Gate Software
MaximumASP
SourceGear - Tools for Developers
.: CounterSoft :.
telerik
 


DotNetNuke Forums
 
  Forum  DotNetNuke® Pro...  Iframe Module [...  Security and IFrame
Previous Previous
 
Next Next
New Post 9/25/2008 2:36 PM
Resolved
User is offline Kmideas
65 posts
10th Ranked


Security and IFrame 

We have a DNN site on which we need to display a registration form and credit card payment processor from another web app. The web app with the payment system is secured with a website certificate. We were thinking of using the IFrame to display the form and payment fields.

Would I need another certificate for the DNN sire with the IFrame?
If both sites have certificates, is the transaction still secure using an IFrame?

Thanks

 
New Post 9/25/2008 3:29 PM
User is offline Vitaly Kozadayev
753 posts
www.continure.com
7th Ranked






Re: Security and IFrame 

If your payment processor domain name is different than your DNN website, browsers will display "Incorrect Certificate" errors: just look here - http://www.dnniframe.com/iframe-samples/ssl-usage.aspx


Vitaly Kozadayev
Principal
Viva Portals, L.L.C.
 
New Post 9/26/2008 8:08 AM
User is offline Kmideas
65 posts
10th Ranked


Re: Security and IFrame 

Okay. If I place the web app at the end of the DNN domain I should be okay.

A related question, I noticed in other threads that a login via IFrame is not possible because passwords are passed via query string.
Is other form data passed the same way... for example a registration form that has name, address, credit card number, etc... is that passed from the Iframe to the registration form in a query string?

Also, as an FYI, I set up a test site using an Iframe and had the login page to a web app appear in the Iframe. I was unable to login using IE 7, but was able to login using FireFox 3.0.1 ...

 
New Post 9/26/2008 9:05 AM
User is offline Vitaly Kozadayev
753 posts
www.continure.com
7th Ranked






Re: Security and IFrame 

The nature of IFRAME object is such that it can only use a QueryString parameters to pass values to the iframe'd page. As a result, all these values are in the plain view of anyone vaguely familiar with HTML. So, yes - if you were to pass someone's name from IFRAME containing page to a page inside an IFRAME, you'd be passing it via SRC attribute of IFRAME tag.

On the other hand, the page inside IFRAME is independent and doesn't need to pass anything to the containing page. So, your creadit card processing is as safe as the inner page's code.

Not sure what you mean in the last point, though. Can you explain it to me, please :) ?


Vitaly Kozadayev
Principal
Viva Portals, L.L.C.
 
New Post 9/26/2008 10:51 AM
User is offline Kmideas
65 posts
10th Ranked


Re: Security and IFrame 
Modified By Kmideas  on 9/26/2008 2:50:03 PM)

I added an Iframe to a site and had one of our web apps login pages as the target URL.

When I used IE7 to access the page with the Iframe and entered the username and password I could not enter the web app.
When I used Firefox and went to the same Iframe page, entered the username and password I logged into my web app.

The Iframe is a module I've never used and wonder if there is a "How To" anywhere. I've read a lot of the threads and have a little (very little) understanding of it, but would like more. I'm particularly interested in how to use query string parameters.

Thanks for your help

 
Previous Previous
 
Next Next
  Forum  DotNetNuke® Pro...  Iframe Module [...  Security and IFrame
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


DotNetNuke® in Sweden
All service of DotNetNuke® in Sweden.
Olsmar Konsult
Verndale - Web Development, Support, Hosting
Since 1998, Verndale has helped hundreds of emerging and midsize businesses maximize the value and reach of their web assets with a comprehensive offering of strategy, design, development, search marketing and support services.
www.verndale.com
Overlook Technology
Website Development, DotNetNuke Consulting, Module Development, Portal Management
OverlookTechnology.com

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP