• 0

Determining if Kerberos auth would be successful using JavaScript


Question

Hi guys,

I have the following scenario: The user requests a web page. He is redirected to a landing page which should determine if the user can successfully authenticate using a Kerberos ticket. If he can, then he should be redirected to his originally requested page. If he can't, I do not wish the user to see the regular browser credentials window, but instead be redirected to a log-in page (after which he will be redirected to his originally requested page).

Any idea how I can test in JS if authentication would be successful and then make the decision then?

Any other ideas would be welcome as well. My server-side will be written in PHP.

Thanks,

6 answers to this question

Recommended Posts

  • 0
  On 25/07/2011 at 07:57, DerpDerp said:

Hi guys,

I have the following scenario: The user requests a web page. He is redirected to a landing page which should determine if the user can successfully authenticate using a Kerberos ticket. If he can, then he should be redirected to his originally requested page. If he can't, I do not wish the user to see the regular browser credentials window, but instead be redirected to a log-in page (after which he will be redirected to his originally requested page).

Any idea how I can test in JS if authentication would be successful and then make the decision then?

Any other ideas would be welcome as well. My server-side will be written in PHP.

Thanks,

You can use JQuery/Ajax and run the PHP script. If successful do one thing if not do another and you can do this JQuery callback

You can use these:

http://api.jquery.com/jQuery.get/

http://api.jquery.com/jQuery.post/

http://api.jquery.com/jQuery.ajax/

  • 0

Thanks for your answer!

Would a XMLHttpRequest suffice?

But correct me if I'm wrong, aren't these HTTP authentications a little ping-pong game? 401 first, then retry then so and so on. Wouldn't the AJAX request stop and fail on the first 401?

Thanks,

  • 0
  On 26/07/2011 at 08:28, C:Amie said:

You need to catch the status code back from the XMLHttpRequest before you execute your client code against the return value (i.e. look for a 200 code). You need to add handlers for other relevant status codes.

Yes, but would catching the initial return code not yield the initial 401 before the ping-pong of authentication (in my case either Kerberos or NTLM)?

  • 0

The web server shouldn't return from its script process until it has an authentication decision. If for some reason you have an asynchronous kerberos proces going on, you'll just have to re-send the request on receipt of a 401 with a longer wait timer defined at the server

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Idiots never imagine their insane actions troubling everyone.  
    • Photo Variants 2.3 by Razvan Serea Photo Variants is an all-in-one photo editor for Windows. Quickly cull, import, and edit your images with powerful tools. Enjoy full layer support, precise retouching features, and a wide range of filters and color adjustments. Create multiple versions of a photo instantly with presets, or design from scratch using vector graphics and advanced editing options. Free for personal and commercial use. Photo Variants key Features: Advanced Adjustment Tools: Provides precise control over image modifications. ​ Extensive Filter Collection: Offers over 99 photo filters to apply various effects. ​ Animated Photo Effects: Enables the addition of dynamic elements to images. ​ Automatic Face Retouching: Includes features for enhancing facial features automatically. ​ Support for Multiple Formats: Compatible with over 100 graphic formats, including RAW and PSD files, allowing users to open, edit, and save in these formats. ​ Drawing and Transformation Tools: Facilitates freehand drawing, erasing, filling, cropping, resizing, rotating, and flipping images. Photo Variants supports a wide array of image formats, making it a versatile tool for all your editing needs. Key supported formats include: Raster Formats: .jpeg, .jpg, .png, .bmp, .gif, .tiff, .webp, .ico, .pcx. Camera RAW: .crw, .cr2, .dng, .nef, .raf, .arw, .orf, .x3f, .raw. Professional Formats: .psd, .ai, .svg, .tga, .pdf, .pcl. Specialized Formats: .dicom, .dcm, .heic, .heif, .avif, .exr, .dds. Other: .wmf, .emf, .xps, .jpeg2000 (.jp2)...etc... With support for these formats, Photo Variants offers seamless editing and flexibility for photographers, designers, and creatives. Photo Variants 2.3 changes: New effects for layers. New shapes and options for brushes. Download: Photo Variants 2.3 | 70.5 MB (Freeware) View: Photo Variants Home page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Internal PSU for these applications is bueno. External would be prone to noise and that is exactly something you do not want.
    • Google may finally be developing an answer to Apple's Live Activities by David Uzondu When Live Activities launched with iOS 16, Apple gave iPhone users a dynamic way to track stuff like sports scores and food deliveries right on the lock screen. Almost two years later, Samsung followed with the "Now Bar," a similar pill-shaped widget on its One UI 7.0 software. Both features are quite useful, solving the same problem of saving you a trip into an app for a quick update. As for user adoption, there are no official numbers, but in 2023, Business of Apps estimated that 41% of iPhone users had already tried Live Activities, with 62% of them rating their experience as "Good" or "Exceptional." Based on that data, it is a popular feature, even with its technical hurdles for developers, like the tight 4KB limit for update data. Now, it looks like Google is finally getting its own version ready for Pixel phones. According to a code teardown by Android Authority, evidence is mounting for a new feature, the so-called Gemini Space, which will likely debut with the Pixel 10 later this year before making its way to older devices. The first clues appeared in a system file from a recent Android beta, named "Ambient Data." This file was found in the firmware for both the Pixel 9 Pro and the Pixel 8 Pro, which suggests current phone owners might not be left out in the cold. What this "Ambient Data" actually does is anyone's guess, but the name itself points toward "contextual information" living on your always-on display. Further digging into the Android System Intelligence app, which powers the Pixel's existing "At a Glance" widget, unearthed more direct connections. Code strings explicitly link "Gemini Space" to new At a Glance capabilities. Android Authority got the finance recap and sports scores, features that have been floating around in rumors for a bit. This has led to a strong theory that Gemini Space could be a rebrand of At a Glance, with more capabilities. Related references also point to an "Ambience Hub," which could function as a more expansive, full-screen summary, much like Samsung's Now Brief complements its Now Bar. As Android Authority notes, you could argue that At a Glance already does this, but its current implementation feels limited compared to the competition. A repositioning of the widget to the bottom of the lock screen was even tested last year, which would make it look a lot like Apple's and Samsung's offerings. If this reporting is on the money, Gemini Space could finally give Pixel users the rich, glanceable updates that other phone users have had for a while.
  • Recent Achievements

    • Week One Done
      Wayne Robinson earned a badge
      Week One Done
    • One Month Later
      Karan Khanna earned a badge
      One Month Later
    • Week One Done
      Karan Khanna earned a badge
      Week One Done
    • First Post
      MikeK13 earned a badge
      First Post
    • Week One Done
      OHI Accounting earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      692
    2. 2
      ATLien_0
      269
    3. 3
      Michael Scrip
      204
    4. 4
      +FloatingFatMan
      169
    5. 5
      Steven P.
      144
  • Tell a friend

    Love Neowin? Tell a friend!