Saturday, March 31, 2012
Themes, Pages, and Master Pages
Why cannot I attach a theme to a master page?
When I define a CSS within a theme and then attach the theme to a page it
seems that I cannot use the CSS definitions directly on that page. Is this
correct? If so, why?
Thanks
Jayin the web.config in the <pages> tag add a styleSheetTheme attribute with th
e
name of your theme. If that isn't what you want to do, you can always
temporarily drop the CSS link directly into the master page for editing and
then remove it when done (unless of course you want it directly on that page
).
"MS News" wrote:
> I am trying to understand some basic things about themes.
> Why cannot I attach a theme to a master page?
> When I define a CSS within a theme and then attach the theme to a page it
> seems that I cannot use the CSS definitions directly on that page. Is thi
s
> correct? If so, why?
> Thanks
> Jay
>
>
I messed up and see my mistake. Everything works as expected and very
nicely.
Jay
"MS News" <someone@.nowhere.com> wrote in message
news:eJWVBajMGHA.740@.TK2MSFTNGP12.phx.gbl...
>I am trying to understand some basic things about themes.
> Why cannot I attach a theme to a master page?
> When I define a CSS within a theme and then attach the theme to a page it
> seems that I cannot use the CSS definitions directly on that page. Is
> this correct? If so, why?
> Thanks
> Jay
>
>
Themes, Pages, and Master Pages
Why cannot I attach a theme to a master page?
When I define a CSS within a theme and then attach the theme to a page it
seems that I cannot use the CSS definitions directly on that page. Is this
correct? If so, why?
Thanks
Jayin the web.config in the <pages> tag add a styleSheetTheme attribute with the
name of your theme. If that isn't what you want to do, you can always
temporarily drop the CSS link directly into the master page for editing and
then remove it when done (unless of course you want it directly on that page).
"MS News" wrote:
> I am trying to understand some basic things about themes.
> Why cannot I attach a theme to a master page?
> When I define a CSS within a theme and then attach the theme to a page it
> seems that I cannot use the CSS definitions directly on that page. Is this
> correct? If so, why?
> Thanks
> Jay
>
>
I messed up and see my mistake. Everything works as expected and very
nicely.
Jay
"MS News" <someone@.nowhere.com> wrote in message
news:eJWVBajMGHA.740@.TK2MSFTNGP12.phx.gbl...
>I am trying to understand some basic things about themes.
> Why cannot I attach a theme to a master page?
> When I define a CSS within a theme and then attach the theme to a page it
> seems that I cannot use the CSS definitions directly on that page. Is
> this correct? If so, why?
> Thanks
> Jay
Monday, March 26, 2012
This forum has reached 25K threads & 1000 pages
Such a waste ......
This is a real getting started question
It is a Windows 2003 server. I am running the Ensim control panel. I have it set to Scripts only. When I remote desktop to the server, and go into IIS Manager, I have the following configuration under Web Extensions:
All Unknown ISAPI Extensions - Prohibited
All Unknown CGI Extensions - Prohibited
Active Server Pages - Allowed
ASP.NET v1.1.4322 - Allowed
Frontpage Server Extensions 2002 - Allowed
Indexing Service - Allowed
Internet Data Connector - Allowed
PERLCGI - Allowed
PERLISAPI - Allowed
PHPCGI - Allowed
Server Side Includes - Allowed
WebDAV - Prohibited
In addition to being new to ASP.NET and ASP pages generally, I recently got this dedicated server, so I am learning about the set-up while I am moving all of the sites I manage over to it. I've bitten off a little bit, I know, but, hey, no better way to learn, than under the gun, right? It forces me to pay attention and learn. I have been wanting to learn more about dynamic pages and database driven sites, and now I am. That said, I'll probably ask a ton of really stupid questions here. Not that I want anyone to build my code for me, just head me in the right direction so I can learn how to do it myself...
Thanks for any help you can give!
Dan
woo. youare jumping in feet first, aren't you? OK. so we've eliminated the extensions issue.
err... doubt you need the IDC or Indexing enabled, btw.
so this is an ASPX file you're atempting to run?
Yes, it is. http://www.pittsburghpipeband.com/800html/MemberLogin.aspx
Incidentally, I found another post on a board that had the same problem. Here's the URL:
http://www.asp.net/Forums/ShowPost.aspx?tabindex=1&PostID=424900
I decided to try the suggestion by AccuBubba in the 3rd reply and after running the command, it fixed the 404 error. I assume that there was a config issue either in the order IIS and ASP.NET and the .NET framework was installed, or more likely that the ASP.NET install was corrupt or unfinished. Now, I am getting a runtime error.
I am about to go back over to the server to make certain that I didn't delete that page accidentally, although, I would think that would bring up another 404 error. I assume it is a security issue, but am unsure of everything I need to check.
By the way, I love what I've seen of your site. I was a little intimidated about what your reply might be after having read the RTFM and the "Should you really be trying this?" but, I am going to learn! Just not going to ask how to make a Hotmail Clone... :)
HMMMMMMMMMMMMMMM, Atrax, maybe I shouldn't be doing this after all.
I have been going over this and over this, and looking at the error page I got as well as the steps I took making this page, it seems I forgot to make my web config file. I'm betting this fixes it.
Not sure if I'm stupid or just hurrying too much. I'll post and let you know though.
OK, I know I'm pretty much talking to myself here. I have to assume that this is a config issue with IIS because I have made several changes to the web.config file (starting with building one in the first place, which I forgot to do.) I got rid of the 404 error. Now, I am getting another error:
Description: An application error occurred on the server. The current custom error settings for this application prevent the details of the application error from being viewed remotely (for security reasons). It could, however, be viewed by browsers running on the local server machine.
Details: To enable the details of this specific error message to be viewable on remote machines, please create a <customErrors> tag within a "web.config" configuration file located in the root directory of the current web application. This <customErrors> tag should then have its "mode" attribute set to "Off". I did this. So, when I remote Desktop to the server, and run the page in IE, it says this:
Description: An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.
Exception Details: System.Web.HttpException: Server cannot access application directory 'c:\Program Files\Ensim\Site Data\pipes\Inetpub\wwwroot\'. The directory does not exist or is not accessible because of security settings.
Source Error:
An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.
Stack Trace:
[HttpException (0x80004005): Server cannot access application directory 'c:\Program Files\Ensim\Site Data\pipes\Inetpub\wwwroot\'. The directory does not exist or is not accessible because of security settings.]
System.Web.HttpRuntime.EnsureAccessToApplicationDirectory() +72
System.Web.HttpRuntime.FirstRequestInit(HttpContext context) +263
[HttpException (0x80004005): ASP.NET Initialization Error]
System.Web.HttpRuntime.FirstRequestInit(HttpContext context) +964
System.Web.HttpRuntime.ProcessRequestInternal(HttpWorkerRequest wr) +128
So, that leads me to believe that permissions or security issues are involved. Am I on the right path? Anything I should try? I have to assume that this being the major issue at this point, and not being the ultimate configuration person, I can handle the rest of it...once I get it to run in the browser.
Saturday, March 24, 2012
This page contains both secure and non secure items.
My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
shows this security alert:
This page contains both secure and non secure items.
Do you want to display non-secure items?
Regardless I answer no (or yes), everything works fine.
We don't like our users see that message because it makes them nervous
without any good reason.
How can I track why the browswer shows that flase security alert?
Thanks,
AlanHi Alan,
Are you using SmartNavigation in the page or referencing scripts that are
outside the Application?
Here's an article on the SmartNav problem:
Error Message When You Submit .aspx Page with SmartNav Under SSL
http://support.microsoft.com/defaul...kb;en-us;318320
"A.M" <nospam1@.online.nospam> wrote in message
news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> Hi,
> My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
> shows this security alert:
> This page contains both secure and non secure items.
> Do you want to display non-secure items?
> Regardless I answer no (or yes), everything works fine.
> We don't like our users see that message because it makes them nervous
> without any good reason.
> How can I track why the browswer shows that flase security alert?
>
> Thanks,
> Alan
>
Are you using frames?
http://support.microsoft.com/defaul...b;EN-US;Q184960
"A.M" <nospam1@.online.nospam> wrote in message
news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> Hi,
> My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
> shows this security alert:
> This page contains both secure and non secure items.
> Do you want to display non-secure items?
> Regardless I answer no (or yes), everything works fine.
> We don't like our users see that message because it makes them nervous
> without any good reason.
> How can I track why the browswer shows that flase security alert?
>
> Thanks,
> Alan
>
No, I don't
"Ken Cox [Microsoft MVP]" <BANSPAMken_cox@.sympatico.ca> wrote in message
news:%23d0KaePTEHA.3552@.TK2MSFTNGP09.phx.gbl...
> Are you using frames?
> http://support.microsoft.com/defaul...b;EN-US;Q184960
> "A.M" <nospam1@.online.nospam> wrote in message
> news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
>
It is not smartnavigation because the warning pops up on one specific page.
I am pasting the page source at the end of this post:
Thanks,
Alan
========================================
=============================
<!-- Template Start-->
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
<HEAD>
<title>Please Wait ...</title>
<meta name="GENERATOR" Content="Microsoft Visual Studio .NET 7.1">
<meta name="CODE_LANGUAGE" Content="C#">
<meta name="vs_defaultClientScript" content="JavaScript">
<meta name="vs_targetSchema"
content="http://schemas.microsoft.com/intellisense/ie5">
<script language="javascript">
self.focus();
function BeginPageLoad()
{
location.href = "LLViewer.aspx?rid=21";
}
</script>
</HEAD>
<body onload="BeginPageLoad()">
<form name="Form1" method="post"
action="LLWait.aspx?redirect=LLViewer.aspx%3frid%3d21" id="Form1">
<input type="hidden" name="__VIEWSTATE"
value=" dDwxNzg0NjA0NTg0Ozs+5wOOcjTIemMpowWPCjq0
XgZxlAA=" />
<P> </P>
<P> </P>
<P> </P>
<P align="center">
<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000"
codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.ca
b#version=6,0,29,0" width="400" height="200" VIEWASTEXT>
<param name="movie" value="/LLC/Images/PleaseWait.swf">
<param name="quality" value="high">
<embed src="http://pics.10026.com/?src=/LLC/Images/PleaseWait.swf" quality="high"
pluginspage="http://www.macromedia.com/go/getflashplayer"
type="application/x-shockwave-flash" width="400" height="200"></embed>
</object>
</P>
<P> </P>
</form>
</body>
</HTML>
<!-- Template End-->
========================================
=============================
"Ken Cox [Microsoft MVP]" <BANSPAMken_cox@.sympatico.ca> wrote in message
news:eH1BFdPTEHA.2408@.tk2msftngp13.phx.gbl...
> Hi Alan,
> Are you using SmartNavigation in the page or referencing scripts that are
> outside the Application?
> Here's an article on the SmartNav problem:
> Error Message When You Submit .aspx Page with SmartNav Under SSL
> http://support.microsoft.com/defaul...kb;en-us;318320
>
> "A.M" <nospam1@.online.nospam> wrote in message
> news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
>
Hi,
the error occurs because browser is fetching content both from secure and
insecure pages. Unless there isn't any clear that comes with HTTP (and uses
SSL that is HTTPS), you just need to remove the HTML snippet by snippet to
test out which part causes the problem.
Teemu Keiski
MCP, Microsoft MVP (ASP.NET), AspInsiders member
ASP.NET Forum Moderator, AspAlliance Columnist
http://blogs.aspadvice.com/joteke
"A.M" <nospam1@.online.nospam> wrote in message
news:edCLHPWTEHA.2128@.TK2MSFTNGP11.phx.gbl...
> No, I don't
> "Ken Cox [Microsoft MVP]" <BANSPAMken_cox@.sympatico.ca> wrote in messa
ge
> news:%23d0KaePTEHA.3552@.TK2MSFTNGP09.phx.gbl...
6
>
This page contains both secure and non secure items.
My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
shows this security alert:
This page contains both secure and non secure items.
Do you want to display non-secure items?
Regardless I answer no (or yes), everything works fine.
We don't like our users see that message because it makes them nervous
without any good reason.
How can I track why the browswer shows that flase security alert?
Thanks,
AlanHi Alan,
Are you using SmartNavigation in the page or referencing scripts that are
outside the Application?
Here's an article on the SmartNav problem:
Error Message When You Submit .aspx Page with SmartNav Under SSL
http://support.microsoft.com/defaul...kb;en-us;318320
"A.M" <nospam1@.online.nospam> wrote in message
news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> Hi,
> My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
> shows this security alert:
> This page contains both secure and non secure items.
> Do you want to display non-secure items?
> Regardless I answer no (or yes), everything works fine.
> We don't like our users see that message because it makes them nervous
> without any good reason.
> How can I track why the browswer shows that flase security alert?
>
> Thanks,
> Alan
Are you using frames?
http://support.microsoft.com/defaul...b;EN-US;Q184960
"A.M" <nospam1@.online.nospam> wrote in message
news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> Hi,
> My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
> shows this security alert:
> This page contains both secure and non secure items.
> Do you want to display non-secure items?
> Regardless I answer no (or yes), everything works fine.
> We don't like our users see that message because it makes them nervous
> without any good reason.
> How can I track why the browswer shows that flase security alert?
>
> Thanks,
> Alan
No, I don't
"Ken Cox [Microsoft MVP]" <BANSPAMken_cox@.sympatico.ca> wrote in message
news:%23d0KaePTEHA.3552@.TK2MSFTNGP09.phx.gbl...
> Are you using frames?
> http://support.microsoft.com/defaul...b;EN-US;Q184960
> "A.M" <nospam1@.online.nospam> wrote in message
> news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> > Hi,
> > My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
> > shows this security alert:
> > This page contains both secure and non secure items.
> > Do you want to display non-secure items?
> > Regardless I answer no (or yes), everything works fine.
> > We don't like our users see that message because it makes them nervous
> > without any good reason.
> > How can I track why the browswer shows that flase security alert?
> > Thanks,
> > Alan
It is not smartnavigation because the warning pops up on one specific page.
I am pasting the page source at the end of this post:
Thanks,
Alan
================================================== ===================
<!-- Template Start-->
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
<HEAD>
<title>Please Wait ...</title>
<meta name="GENERATOR" Content="Microsoft Visual Studio .NET 7.1">
<meta name="CODE_LANGUAGE" Content="C#">
<meta name="vs_defaultClientScript" content="JavaScript">
<meta name="vs_targetSchema"
content="http://schemas.microsoft.com/intellisense/ie5">
<script language="javascript">
self.focus();
function BeginPageLoad()
{
location.href = "LLViewer.aspx?rid=21";
}
</script>
</HEAD>
<body onload="BeginPageLoad()">
<form name="Form1" method="post"
action="LLWait.aspx?redirect=LLViewer.aspx%3frid%3d21" id="Form1">
<input type="hidden" name="__VIEWSTATE"
value="dDwxNzg0NjA0NTg0Ozs+5wOOcjTIemMpowWPCjq0XgZxlAA=" /
<P> </P>
<P> </P>
<P> </P>
<P align="center">
<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000"
codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.ca
b#version=6,0,29,0" width="400" height="200" VIEWASTEXT>
<param name="movie" value="/LLC/Images/PleaseWait.swf">
<param name="quality" value="high">
<embed src="http://pics.10026.com/?src=/LLC/Images/PleaseWait.swf" quality="high"
pluginspage="http://www.macromedia.com/go/getflashplayer"
type="application/x-shockwave-flash" width="400" height="200"></embed>
</object>
</P>
<P> </P>
</form>
</body>
</HTML>
<!-- Template End--
================================================== ===================
"Ken Cox [Microsoft MVP]" <BANSPAMken_cox@.sympatico.ca> wrote in message
news:eH1BFdPTEHA.2408@.tk2msftngp13.phx.gbl...
> Hi Alan,
> Are you using SmartNavigation in the page or referencing scripts that are
> outside the Application?
> Here's an article on the SmartNav problem:
> Error Message When You Submit .aspx Page with SmartNav Under SSL
> http://support.microsoft.com/defaul...kb;en-us;318320
>
> "A.M" <nospam1@.online.nospam> wrote in message
> news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> > Hi,
> > My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE 6
> > shows this security alert:
> > This page contains both secure and non secure items.
> > Do you want to display non-secure items?
> > Regardless I answer no (or yes), everything works fine.
> > We don't like our users see that message because it makes them nervous
> > without any good reason.
> > How can I track why the browswer shows that flase security alert?
> > Thanks,
> > Alan
Hi,
the error occurs because browser is fetching content both from secure and
insecure pages. Unless there isn't any clear that comes with HTTP (and uses
SSL that is HTTPS), you just need to remove the HTML snippet by snippet to
test out which part causes the problem.
--
Teemu Keiski
MCP, Microsoft MVP (ASP.NET), AspInsiders member
ASP.NET Forum Moderator, AspAlliance Columnist
http://blogs.aspadvice.com/joteke
"A.M" <nospam1@.online.nospam> wrote in message
news:edCLHPWTEHA.2128@.TK2MSFTNGP11.phx.gbl...
> No, I don't
> "Ken Cox [Microsoft MVP]" <BANSPAMken_cox@.sympatico.ca> wrote in message
> news:%23d0KaePTEHA.3552@.TK2MSFTNGP09.phx.gbl...
> > Are you using frames?
> > http://support.microsoft.com/defaul...b;EN-US;Q184960
> > "A.M" <nospam1@.online.nospam> wrote in message
> > news:upfpDoNTEHA.3608@.TK2MSFTNGP11.phx.gbl...
> > > Hi,
> > > > My ASP.NET application uses SSL on IIS6. up on visiting some pages, IE
6
> > > shows this security alert:
> > > > This page contains both secure and non secure items.
> > > Do you want to display non-secure items?
> > > > Regardless I answer no (or yes), everything works fine.
> > > > We don't like our users see that message because it makes them nervous
> > > without any good reason.
> > > > How can I track why the browswer shows that flase security alert?
> > > > > Thanks,
> > > Alan
> >
Thursday, March 22, 2012
Thoughts about using Session variables for login security?
pages.
In my login page's submit button I just say if the "password is correct"
then...
session("IsAdmin") = True
In my admin only pages I check if session("IsAdmin") = True
If it's NOT then I redirect them to the login.aspx page.
Is this solution pretty solid, or is it easy to hack? I keep the password
in the web.config appsettings section so it's easy to change.
I know I could use Membership stuff, but I'm just doing a simple, quick
website.
Your thoughts are appreciated!Hello Bobby,
> I am creating a simple website with a login page and some "admin only"
> pages.
> In my login page's submit button I just say if the "password is
> correct"
> then...
> session("IsAdmin") = True
> In my admin only pages I check if session("IsAdmin") = True If it's
> NOT then I redirect them to the login.aspx page.
> Is this solution pretty solid, or is it easy to hack? I keep the
> password in the web.config appsettings section so it's easy to change.
> I know I could use Membership stuff, but I'm just doing a simple,
> quick website.
Membership is there, membership is quick and membership works out of the
box from the web.config if you need it to.
My experience is that this quick and simple website will run for the coming
20 years and that every time you need to change somthing you hoped you did
it the right way first time round...
--
Jesse Houwing
jesse.houwing at sogeti.nl
I've done the same thing in the past. There is one and only quesion
you need to ask: "is this doing what I need it to?" From your post the
answer is "yes," so you're good. But I see you're asking "is it easy
to hack?"
And the answer is a resounding "no." Session variables are stored in
the server's memory. In order to access them a hacker would need to
hack the server itself and gain access to it's memory. If that
happens, having them view your session variables would be the very
least of your concerns.
On Mar 5, 2:33=A0pm, "Bobby Edward" <t...@.test.com> wrote:
> I am creating a simple website with a login page and some "admin only"
> pages.
> In my login page's submit button I just say if the "password is correct"
> then...
> session("IsAdmin") =3D True
> In my admin only pages I check if session("IsAdmin") =3D True
> If it's NOT then I redirect them to the login.aspx page.
> Is this solution pretty solid, or is it easy to hack? =A0I keep the passwo=[/color
]
rd
> in the web.config appsettings section so it's easy to change.
> I know I could use Membership stuff, but I'm just doing a simple, quick
> website.
> Your thoughts are appreciated!
I'd look at Jesse's recommendation about using the built-in membership
system in ASP.Net 2.0 if you really want to have some flexibility. You can
then use Roles to manage your users. For administrators, you can create an
Admin role and assign the users to that role. Then all you have to do is
test if the user is in that role. Actually, better yet, you can set the
authorization section of the web.config file so that only certain users or
roles have access to particular files or folders. This let's you tweak
security in a config file without worrying about coding it in every single
page.
Hope this helps,
Mark Fitzpatrick
Microsoft MVP - Expression
"Bobby Edward" <test@.test.com> wrote in message
news:%23dULGfvfIHA.1188@.TK2MSFTNGP04.phx.gbl...
>I am creating a simple website with a login page and some "admin only"
>pages.
> In my login page's submit button I just say if the "password is correct"
> then...
> session("IsAdmin") = True
> In my admin only pages I check if session("IsAdmin") = True
> If it's NOT then I redirect them to the login.aspx page.
> Is this solution pretty solid, or is it easy to hack? I keep the password
> in the web.config appsettings section so it's easy to change.
> I know I could use Membership stuff, but I'm just doing a simple, quick
> website.
> Your thoughts are appreciated!
>