Http Modules Integrated into the IIS 7 Processing Pipeline
Q1 -IIS7 by default automatically registers the FormsAuthenticationModule (which is defined in the root web.config), but does the term "Http module integrated into the IIS 7 processing pipeline" mean only when that registered module is also configured to work with nonAsp applications .Net?
In my opinion, if a module is not configured to work with nonAsp.Net applications, even if it is automatically registered by IIS 7, then we cannot say that it is integrated into the IIS 7 processing pipeline ?!
Q2
A) IIS7 automatically registers some of the modules defined in the root web.config file. If we configure (via the IIS7 manager) the UrlAuthorizationModule (which is defined in the root web.config and which IIS 7 registers by default) to be used with nonAsp.Net applications as well, then IIS7 puts the following entry in the root web.config file:
<modules>
<remove name="UrlAuthorization" />
<add name="UrlAuthorization" type="System.Web.Security.UrlAuthorizationModule" preCondition="" />
But why did IIS 7 include the item as well <remove name="UrlAuthorization" />
?
B) I am assuming that if we then change our mind and decide to use this module only with Asp.Net applications, we can safely remove the following element:
<add name="UrlAuthorization" type="System.Web.Security.UrlAuthorizationModule" preCondition="" />
from the root web.config application, as now our application can use the UrlAuthorizationModule defined in the root web.config ?!
Q3
I understand that IIS7 by default registers the FormsAuthenticationModule defined in the root web.config file, but suppose we registered another FormsAuthenticationModule in the web.config file that is contained in the root directory of some web application.
- I am assuming that when a request for a webpage is received, two instances of FormsAuthenticationModule will be executed for that request?
thanks
EDIT:
A1.
"integrated" and "classic" processing pipelines are a feature of the application pool. It is correct that modules can only be configured to run in "integrated" pipelines.
My question was about IIS 7 in integrated mode. Specifically, my book uses the term "Http Module Integrated into the IIS 7 Processing Pipeline" to describe a situation where a custom Http handler has been registered with IIS 7 (running in integrated mode). But it doesn't say if this term refers to a situation where this registered handler is configured to work with nonasp.net applications as well, or do we also use this term when a registered Http handler is configured to only work with Asp.Net applications?
A2. B. Yes, you can remove "delete" as well as "add" lines. This is what the GUI will do if you change it to inherit the settings.
But in my case, IIS 7 does not remove
<add name="UrlAuthorization" type="System.Web.Security.UrlAuthorizationModule" preCondition="" />
from applications root web.config file, it just changes the value of the preCondition attribute back to "managedHandler"
A3. I think you will get an error if you try to add 2 modules that have the same "name" attribute. If you really want it there twice, change the "name" of the second one.
I'm sorry, I have to be more specific, but my question was about a situation where two modules would have different names.
So, in this case, two instances of FormsAuthenticationModule will be launched?
thanks
a source to share
Just noticed that you are using Stackoverflow. Please check my latest answers at iis.net.
http://forums.iis.net/t/1157580.aspx
The important thing is that applicationHost.config and root web.config actually have a different meaning, so don't be confused if the item appears in both files. It really has different meanings.
a source to share
A1. "integrated" and "classic" processing pipelines are the property of the application pool. It is correct that modules can only be configured to run in "integrated" pipelines.
A2. A. To change the preCondition attribute, he had to remove the first version and add it again.
A2. B. Yes, you can remove "delete" as well as "add" lines. This is what the GUI will do if you change it to inherit the settings.
A3. I think you will get an error if you try to add 2 modules that have the same "name" attribute. If you really want it there twice, change the "name" of the second one.
a source to share