2005-01-31 Zoltan Varga <vargaz@freemail.hu>
[mono.git] / mcs / class / System.Web / System.Web.Security / FormsAuthenticationModule.cs
index 0caac1a584c8b28df918b66065025e8c10c52ffb..ac9f3c31327939eee985b6195729149a08c49e2a 100644 (file)
@@ -7,6 +7,27 @@
 // (C) 2002 Ximian, Inc (http://www.ximian.com)
 //
 
+//
+// Permission is hereby granted, free of charge, to any person obtaining
+// a copy of this software and associated documentation files (the
+// "Software"), to deal in the Software without restriction, including
+// without limitation the rights to use, copy, modify, merge, publish,
+// distribute, sublicense, and/or sell copies of the Software, and to
+// permit persons to whom the Software is furnished to do so, subject to
+// the following conditions:
+// 
+// The above copyright notice and this permission notice shall be
+// included in all copies or substantial portions of the Software.
+// 
+// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
+// EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
+// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
+// NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
+// LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
+// OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
+// WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
+//
+
 using System;
 using System.Security.Principal;
 using System.Text;
@@ -18,8 +39,6 @@ namespace System.Web.Security
 {
        public sealed class FormsAuthenticationModule : IHttpModule
        {
-               bool noForms;
-
                public void Dispose ()
                {
                }
@@ -36,10 +55,9 @@ namespace System.Web.Security
                        HttpContext context = app.Context;
                        AuthConfig config = (AuthConfig) context.GetConfig ("system.web/authentication");
                        if (config.Mode != AuthenticationMode.Forms) {
-                               noForms = true;
                                return;
                        }
-                               
+
                        string cookieName = config.CookieName;
                        string cookiePath = config.CookiePath;
                        string loginPage = config.LoginUrl;
@@ -64,7 +82,12 @@ namespace System.Web.Security
                                return;
 
                        FormsAuthenticationTicket ticket = FormsAuthentication.Decrypt (cookie.Value);
-                       ticket = FormsAuthentication.RenewTicketIfOld (ticket);
+                       if (ticket == null || ticket.Expired)
+                               return;
+
+                       if (config.SlidingExpiration)
+                               ticket = FormsAuthentication.RenewTicketIfOld (ticket);
+
                        context.User = new GenericPrincipal (new FormsIdentity (ticket), new string [0]);
 
                        cookie.Value = FormsAuthentication.Encrypt (ticket);
@@ -77,15 +100,15 @@ namespace System.Web.Security
 
                void OnEndRequest (object sender, EventArgs args)
                {
-                       if (noForms)
-                               return;
-
                        HttpApplication app = (HttpApplication) sender;
                        HttpContext context = app.Context;
                        if (context.Response.StatusCode != 401 || context.Request.QueryString ["ReturnUrl"] != null)
                                return;
 
                        AuthConfig config = (AuthConfig) context.GetConfig ("system.web/authentication");
+                       if (config.Mode != AuthenticationMode.Forms)
+                               return;
+
                        StringBuilder login = new StringBuilder ();
                        login.Append (UrlUtils.Combine (context.Request.ApplicationPath, config.LoginUrl));
                        login.AppendFormat ("?ReturnUrl={0}", HttpUtility.UrlEncode (context.Request.RawUrl));