NET ENVIRONMENT BASED ON THE MVC AJAX SOLUTION

Introduction to the second Internet: scriptcript extraordinary understanding, at least, its web development javascript web development appear competent enough to return to the contents of the PAGE of callbehind updates, so there is certainty DEV threshold increases when the Ajax-based mechanism to stop when DEV , under the original method based on postbehind time, asp.net source code from the backend logic (Model), aspxPAGE (View), aspx.cs (Controller) MVC framework consisting of failure in fact, when callbehind return data, either in the client end web development web development using javascript to return the content to appear updated analysis, or server-side configuration is necessary ... in the body: 1, difficult background
Currently, more and more people start trying to stop non-Based Ajax refresh WebDEV, however,. Net environments, the actual use of Ajax is not easy as unusual, mainly estimated by the following part of the reason is due to:
• Since the Ajax web development javascript-based nature of web development, making the need for javascript DEV Zhe development Feibixunchang understanding of network development network, at least, the javascript development web development network appear on the callbehind competent enough to return to the contents of the PAGE updates, so the DEV's determine the degree of increase in the threshold there is
* Ajax-based mechanism to stop the DEV when when under the original method based on postbehind when, / 'target =' _blank 'class =' infotextkey '> asp. Net from the back-end logic (Model), aspxPAGE (View), aspx.cs ( Controller) MVC framework consisting of failure in fact, when callbehind return data, either in the client-side javascript web development web development by parsing the content returned by an update, or server-side structure is necessary to better compete in the complete source code for static pages, and then directly from the web development javascript web development constructed to a good set of static pages PAGE object, it is clear that as a result, there should be a function of the easiest callbehind, should a lot of source code, and is relatively random contest source code, even in the difficult coming asp.net2.0 still not been effectively resolved
2 The purpose of this
This paper aims to fully conducive to the existing asp.net ajax own characteristics and features, made for a stop under the asp.net ajax the webDEV the MVC-based solutions to the following main objectives:
· Asp.Net Ajax environment for a clear MVC architecture
Reduced everyone too much javascript coding web development web development to reduce dependence on the threshold of English
• Flexible support of the daily DEV ajax mode method
3, difficulty planning
How to appear above the main purpose?
1) To xmlhttprequest for a better package, so call the method is more simple;
2) Try to update the data in the server side to stop the construction, but also to avoid the hand each time to return data structure, therefore, to expect did not score the full application of UserControl, the UserControl as the "View", corresponding to the document as by the ascx.cs " Controller ", consisting of MVC is also a contest as a clear;
4, difficult to solve
Based on the above ideas, a person to the group following a class library to simplify the process:
Source Code Analysis:
1) First in the client side, AjaxHelper.js encapsulates the xmlhttprequest, and will be available to help a
Sequence into the form param1 = v1 ¶ m2 = v2 & ... form for the post of parameters;
Update r (ajaxTemplate, output, params, onComplete) parameters for the call once callbehind
ajaxTemplate (required): Specifies the path UserControl run demand function
output (optional): Fill the prescribed label to return the data reference or IDvalue
params (optional): form param1 = v1 ¶ m2 = v2 & ... the post parameters
onComplete (optional): returns the data can be used to stop the special treatment of the callback parameter, the parameter formatting function (str), str for the returned data
SerializeForm (form) parameters for the sequence of
form: no result is specified reference or IDvalue
2) In the server side, Ajax.aspx documentation package for the specified by the client ajaxTemplate UserControl call, the rest of the specific logic function in a particular UserControl and ascx.cs appeared in;
3) as a callbehind specific run, the English we simply PAGE reference AjaxHelper.js, and in the specified location through the web development web development javascript: Update r (ajaxTemplate, output, params, onComplete) to stop calling, if the demand Stop a form submission, you can call the javascript web development web development: SerializeForm (form) sequence of the form and pass params, of course, did not score manually constructed params, and returns the data specified by set output or through the practical application of the PAGE onComplete custom processing.
4) The full use of UserControl, means that the results did not make full use of existing side asp.net controls and data binding mechanisms, as a matter of fact, has largely simplified the return data structure, in ascx.cs, after Request.Form [ParamName] visit to the client side will be able to pass the params, then visit the logic source code for the source data.

THE PRACTICAL APPLICATION OF PROGRAM RESOURCES, ASP.NET APPLICATION SECURITY MODEL VISIT

The second Internet Guide: Framework, generally did not result from the logical framework is divided into that layer, business logic and data visiting layer; client process to visit the actual use of resources, their authentication and authorization is bound to span multiple levels. This article discuss the practical application of procedures SP.NET application resources application security model visit 2. Resources WEB visiting the practical application of identification procedures of foreign assistance to the client's typical resources include: Web server resources, such as Web pages, Web services, and static resources (static Web pages and images). Database resources, such as the text for ...: Summary: This paper describes. NET WEB application of the practical application of procedures for application of the model species, compare their advantages and disadvantages of proposed selection mechanism.
KEYexpress: the trusted security model sub-model to imitate / ASP.NET application sub-model commissioned by the practical application of WEB application
1. Introduction
ASP.NET WEB Application Application is the practical application of procedures are usually multi-system framework, the general did not result from the logical framework is divided into that layer, business logic and data visiting layer; client process to visit the actual use of resources, their authentication and authorization necessarily span multiple levels. This article discuss the practical application of procedures SP.NET application application security model resource visit
2. Resources visiting logo
WEB practical use of foreign assistance program to the client's typical resources include:
Web resources such as Web pages, Web services, and static resources (static web pages and images). 
Resources, such as the data for each user or the practical application of program-level data. 
Internet resources, such as remote document resource. 
Resources, such as, the event log and configuration documentation.
The practical application of procedures across the client layer to visit this part of the resources, to have a logo through all layers. That the identity of visitors to resources, including:
Original identity of the caller identity of the caller is the original and subsequent access through each layer. 

Process of identification of local resources is the application of visits and calls the downstream stop the current process ID. The feasibility of this approach relies on to cross the border, as the process identity must be the purpose of system identification. This needs to stop calling the following two methods:
Interface with one win in the security domain
Cross-win interface security domain - application and domain trust accounts, or there is no link to the application of trust duplicate user name and password. 
This method applies a service account the (fixed) service account. For example, the database's visit, the service account is estimated that by connecting to the database components that a regular SQL database user name and password. 
When the demand for fixed win the interface ID should be the actual application of Enterprise Services server application program. 
Custom logo does not win the interface when the account is available, the application did not score there Iprincipal and Iidentity construct their own identity, no results contain detailed information about the security context.
3. Resource visiting model
3.1 The trusted subsystem model
Figure 1 shows, in this model, the original caller's security context does not flow through the operating system level services, but application service layer in the middle of a fixed identity to visiting the downstream services and resources. Trusted subsystem model gets its name from the fact that a: the downstream services (estimated to be a database) Trust upstream services that allow the caller to stop authorization. The example in Figure 1, the database layer on the caller trust the authority to stop and allow only authorized caller ID visit the database of trusted applications.
3.1.1 Resource visiting model
In the trusted subsystem model, the resource visit the following pattern:
Authentication of users to stop the user mapping for the role authorization based on role membership to contact to stop applying a fixed trusted identity downstream resources visit
3.1.2 fixed identity
Together resources for visiting the control device downstream system of fixed identity, no results application process identity, application did not score a pre-set win interface account - service account to help. For the SQL database server resource control device, which means win on the SQL database server interface authentication.
Usually used when the application process ASP.NET application identity application process identity (ASPNET account for tacit knowledge). The actual practical application, we often need to change the ASPNET account to a more secure password, and the SQL database server MIRROR create an ASP.NET application with the account application process that matches the account interface on the match win. Specific tips are as follows:
Edit in% windr% / Microsoft.NET application application / Framework/v1.1.4322/CONFIG Machine.config under the list of documents, willelement to reconfigure the password attribute, its default value to ; or through ASPNET_setreg.exe props, the user name and password saved to the registry, configure the following: < !-enable = "true" UserName = "Registry: HKLM / SOFTWARE / YourAPP / processsModel / ASPNET_SETREG, userName" passexpress = "Registry: HKLM / SOFTWARE / YourAPP / processsModel / ASPNET_SETREG, passexpress" ->
Another part of the application of the practical application of procedures specified SQL database account (char string in the connection name and password specified by the user) to visit SQL database server. In this case, the database must be configured for SQL database authentication. Saved in the configuration file needs the connection string encryption char.
3.2 Imitation / delegation model
Shown in Figure 2, the application copy / delegation model, a service or component (usually located in the business service layer logic) in the visit prior to the next downstream services, the application operating system copy function to mimic the client identity. If the service is on the same computer, the application of imitation is sufficient, if the downstream service is located on a remote computer applications also demand commission, the security context of the downstream resource is visiting the client's context.
3.3 Select resources to visit Model
Trial of two resources, such as visiting the model shown in Table I.
Trusted subsystem model to imitate / delegation model
The upper back-end services, trust audit function, if the infringement of the middle layer, the back-end resources vulnerable. Back-end service performance for each caller did not stop the authentication, authorization, security is good.
Scalability to support connection pooling, better scalability. Does not support connection pooling, scalability poor.
Control of the back-end ACL ACL configuration for a single entity to stop, control workers less.Each user must be granted the appropriate visit level, back-end resources and the number of users increases, the control of workers cumbersome.
Difficulties do not delegate the performance. Demand for commission. Most of the security services to help does not support delegates.
In most practical use of Internet programs and the practical application of a large intranet application process will be trusted subsystem model, mainly because this model can support scalability. Imitation / delegation model for small systems tend to. For this part of the practical application of procedures, scalability is not that the main planning factors, the main factor is the audit plan.