2007-03-13
asp中利用window.open时session丢失的问题
关键字: ASPFIX: Windows Opened by Script Lose Authentication or Session
| Article ID | : | 196383 |
| Last Review | : | June 21, 2004 |
| Revision | : | 2.0 |
This article was previously published under Q196383
On This Page
SYMPTOMS
When windows are opened from script in an HTML page using window.open or ShowModalDialog, Internet Explorer responds by prompting users to enter their username and password every time a new window is created. This happens even though the user already entered a correct username and password and successfully authenticated with the Web server.
New windows may also lose Web server session information, creating a new session or reusing an older, incorrect session from a separate Internet Explorer instance.
Also, if the new window contains a Java applet that accesses static information from a class, it may not be able to share that information with an applet in another window.
These symptoms do not appear if the Windows Desktop Update is installed and the browser is not set to "Browse In New Process."
New windows may also lose Web server session information, creating a new session or reusing an older, incorrect session from a separate Internet Explorer instance.
Also, if the new window contains a Java applet that accesses static information from a class, it may not be able to share that information with an applet in another window.
These symptoms do not appear if the Windows Desktop Update is installed and the browser is not set to "Browse In New Process."
CAUSE
When asked to create new windows through script, Internet Explorer might create the window in the wrong Internet Explorer process. Because authentication credentials and the temporary cookies used for session identification are cached per process, new windows need to re-authenticate and start a new session if they don't open in the same process as their opening window.
This behavior can appear random; the determined process for new windows is dependent on several variables, including timing and browser configuration.
This behavior can appear random; the determined process for new windows is dependent on several variables, including timing and browser configuration.
RESOLUTION
To resolve this problem, upgrade to the latest version of Internet Explorer or Microsoft Windows NT 4.0 Service Pack 6a (SP6a). You can download the latest version of Internet Explorer from the following Microsoft Web site:
However, Web servers should avoid relying on this as a solution. Web sites that expect users to change browser settings will have a negative user experience, particularly when other sites require a different value for the same settings. Users in corporate environments may not even have control over this setting. Furthermore, disabling "browse in new process" can affect the stability of the system shell and some users may need to use "Browse In New Process" when they are working with pages that contain a lot of Active Content.
Note that all session-managed pages should be set to expire immediately. Some session inconsistencies can result when pages are pulled from the cache rather than from the Web server.
http://www.microsoft.com/windows/ie/ (http://www.microsoft.com/windows/ie/)
Disabling the "Browse In New Process" browser setting in the Advanced tab of the Internet Options will alleviate most of the symptoms described in this article. However, Web servers should avoid relying on this as a solution. Web sites that expect users to change browser settings will have a negative user experience, particularly when other sites require a different value for the same settings. Users in corporate environments may not even have control over this setting. Furthermore, disabling "browse in new process" can affect the stability of the system shell and some users may need to use "Browse In New Process" when they are working with pages that contain a lot of Active Content.
Note that all session-managed pages should be set to expire immediately. Some session inconsistencies can result when pages are pulled from the cache rather than from the Web server.
STATUS
Microsoft has confirmed that this is a bug in the Microsoft products that are listed at the beginning of this article. This bug was corrected in Internet Explorer 4.01 Service Pack 2 and Internet Explorer 5.
MORE INFORMATION
Steps to Reproduce Behavior
| 1. | Create the following Active Server Pages (ASP) page on an Internet Information Server machine, version 3.0 or later, in a scripts directory:
|
| 2. | Verify that the "Browse In New Process" setting is selected in Internet Explorer on the client machine. This setting is in the Browser Settings section in the Advanced tab of the Internet Options dialog box. |
| 3. | On the client machine, launch exactly one Internet Explorer instance. Navigate to the ASP page created in step 1. Click the "WindowOpen" button to execute window.open and create a new window. Note that the ASP Session ID matches in both child and parent window. |
| 4. | Create a new Internet Explorer instance by invoking Internet Explorer from the Start menu or Desktop icon. Again, navigate to the ASP page created in step 1. Click the "WindowOpen" button. Note that the ASP Session ID does not match in both child and parent window of the new process. In some cases, this may be the session ID of the first pair of Internet Explorer windows. |
REFERENCES
Similar symptoms can occur when working with Office documents or other Active Document servers in a Web environment.
For additional information, click the following article number to view the article in the Microsoft Knowledge Base:
For additional information, click the following article number to view the article in the Microsoft Knowledge Base:
185978 (http://support.microsoft.com/kb/185978/) FIX: Double GET requests and cookies are lost with Word 2000 or Excel 2000
APPLIES TO
| • | Microsoft Internet Explorer 4.0 128-Bit Edition |
| • | Microsoft Internet Explorer 4.01 Service Pack 2 |
| • | Microsoft Internet Explorer 4.01 Service Pack 1 |
Keywords: |
kbbug kbfix kbqfe kbie500fix KB196383 |
发表评论
- 浏览: 9583 次

- 详细资料
搜索本博客
最近加入圈子
最新评论
-
JSF的问题,希望那位可以 ...
验证器出现了错误,在validate phase这个阶段,获得的下拉列表为空,所 ...
-- by snakeskin -
JSF的问题,希望那位可以 ...
断点跟踪一下。。 某些是空的
-- by penghao122 -
JSF的问题,希望那位可以 ...
表达式:#{userBean.countyId}计算的值没有包含在下拉列表的值中 ...
-- by jones -
JSF的问题,希望那位可以 ...
问题是第一次打开和第一次操作都没有问题,但是当操作一次在下拉后就出现了错误,错误 ...
-- by bingxue2332 -
struts直接转到action里面 ...
你直接用requst.setAttribute();设置一个就行了
-- by hgq0011


Back to the top




评论排行榜