How to identify the direct url from user to HttpServer and the redirected url from WAS to HttpServer?
0 posts in topic
Flat View  Flat View
TOPIC ACTIONS:
 

Posted By:   Subramaniam_V
Posted On:   Monday, January 10, 2005 10:53 AM

All static pages (download/attachment,images,htmls request) are being served by HttpServer. So all the attachment files are downloadable without logging in the site which is not desirable since some files contain info for authorized users only. To overcome this problem I'm making the following changes to the existing logic. a) Make the web-path configuration changes such that all the download request will hit AppServer b) Check the User authorization to view the requested download file. c) If the user is authorized, then show the download file to the user or display error/login page. Question; Once the user is authorized, I'm redirecting (resp.sendRedirect()) to /download/sample.pdf and have added    More>>

All static pages (download/attachment,images,htmls request) are being served by HttpServer. So all the attachment files are downloadable without logging in the site which is not desirable since some files contain info for authorized users only.

To overcome this problem I'm making the following changes to the existing logic.

a) Make the web-path configuration changes such that all the download request will hit AppServer
b) Check the User authorization to view the requested download file.
c) If the user is authorized, then show the download file to the user or display error/login page.

Question;

Once the user is authorized, I'm redirecting (resp.sendRedirect()) to /download/sample.pdf and have added /download/ alias in httpd.conf. So that the redirected request will be handled by the Httpserver.

How do I differentiate between the direct request to HttpServer (user enters the url /download/sample.pdf directly in the browser without logging in the site) and the redirected request to HttpServer (resp.sendRedirect("/download/sample.pdf") from WAS. If the request is direct show up the loging page and if it's requested from WAS then I need to show the pdf file.

In short If i have a url of the form /resource/download/x.pdf which can be re-directed by Websphere or user can type-in the url in the browser...isthere any way to identify from where the request cam from at HTTP Server level?

   <<Less
About | Sitemap | Contact