Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
Articles
Recherche: 

Considerations when building Web applications Part IV
Michel Fournier, April 1, 2003
In this article, I will proceed with considerations about HTTP server variables being received from a browser and about considerations for opening new windows in your Web application. Relying on the protocol or not When it first started, we didn't ask that question to ourselves as to know ...
In this article, I will proceed with considerations about HTTP server variables being received from a browser and about considerations for opening new windows in your Web application.

Relying on the protocol or not

When it first started, we didn't ask that question to ourselves as to know if we could rely on specific HTTP server variables when a request was sent to a Web server. It was automatic and we were able to benefit of specific data as is being sure it was accurate. However, the introduction of specific options available for customization in browsers and the addition of specific tools that can be installed on a PC, this is no longer totally accurate.

In the first part of this article, we will discuss about the following HTTP fields:

Field Description
REMOTE_ADDR Returns the IP address of the remote host making the request
HTTP_REFERER Returns the original URL when a redirect has occurred
HTTP_COOKIE Returns the cookie string included with the request

REMOTE_ADDR

Many Web developers are making use of the REMOTE_ADDR variable to collect the IP of origin of the transaction. Despite the fact that in many occasions, this could represent the actual IP of the PC which has launched the transaction, in several cases, it won't be. Note that it is always good to track it for monitoring purposes as it would represent at least one point along the route which was used to submit the transaction and could lead, after investigation, to the IP of origin.

Take the example of a corporate infrastructure well established under a firewall. That would mean any IP received from any transaction from that corporation would be the one that the firewall has been configured to use. So, you would end up with the same IP coming in from various employees of that company.

Our next example are users using a proxy service from their ISP in order to hide their IP. That is a practice that is commonly used now for people known as troublemakers, hackers and related terminologies. Basically, their ISP could allow them to benefit of a specific proxy and whenever they will send a transaction, the IP received would be the one from that specific proxy. Note that the same approach could be used assuming someone would own his own proxy either individually or within a corporate environment.

So, there shouldn't be any assumption that this could represent the IP of origin even if you know that this is a user that is usually working from home within one single PC connected to the Internet.

One more example of such situation is when people are connected to a VPN connection and using that connection to access a specific Web site. Within a VPN connection, several users can connect to a server and this could add to the confusion of the IP received. Some users would want to use a VPN connection, assuming they would benefit of a stronger bandwidth ability, to hide again their IP of origin or to simply to some tests when being connected to such environment.

So, those are various scenarios that it might be good to collect the IP for specific validations and monitoring purposes, but what you collect is not exactly what you get.

HTTP_REFERER

The HTTP_REFERER server variable is another variable being used for many purposes. This variable returns the original URL when a redirect has occurred. This is a general definition used for this variable but it is more like the URL which was previously loaded in the same window environment.

But, no matter its definition, this is probably one of the most confused cause of problems for Web developers. The way this works and the interference caused by several third party tools is making this variable practically useless.

First of all, if a user types directly into the browser URL, you will receive a blank value for that variable, even if he was previously on a page from your site. The only time you can get a value is when the transaction is launched from the content of the page itself.

But, that is true as long as the transaction is being refreshed within the same window. That means if you have a Javascript that generates the transaction to be opened in a new window, you will also get a blank value as this server variable will exist only from within the same window.

But, the biggest cause of problems when making use of that value and a big percentage of support issues that needs to be supported is when the user is using a tool such as Zone Alarm Pro or Norton Internet Security which allows the user to enable specific privacy features. Basically, those tools sit between the browser and what is being sent to the server. That means, the browser relies on a protocol to send specific material but this is not what reaches the server.

So, if your application relies on the HTTP_REFERER variable for specific validation or related topics, you might soon have to support those users who will simply don't understand why it doesn't work for them. It's not that they wanted to do that specifically on your Web site, but the fact that they enabled that privacy option in a tool such as mentioned above, will auto default the same setting everywhere they go on the Internet. So, as they don't realize that specific Web applications might need that server variable to remain untouched, they will find themselves in such a situation soon or later.

Once discovered, either from the support issue or from their own knowledge of the situation, they usually can adjust that setting with a sub setting that will allow them to open a gate for specific Web site where this privacy option will not apply.

So, as it is the case of REMOTE_ADDR, I would only recommend the use of that variable for adding additional data to your audit files but not to rely on it in your application.

HTTP_COOKIE

The HTTP_COOKIE server variable is widely used on the Internet. This variable returns the cookie string included with the request. What many would consider as the first fear of the Internet, when browsing to several servers, it was causing more problems a few years ago than today.

Originally supported by several browsers at first, users are able to disable the cookie functionality by one simple click. Additionally to that, you will now find additional tools which would support that ability as well.

So, if your application relies on this server variable, make sure it is well known to your users that this is a requirement. Include it in your technical guidelines and elsewhere, if you wish, such as where the user is authenticating.

Opening new windows

This is, from my POV, the most serious issue right now that Web developers have to support in their application. Because of the SPAM revolution, all kind of tools have seen the light of day to counter attach any types of approaches that some specific Web site will use to SPAM their users.

The biggest problem, and caused by a bad perception of those who build those tools, are the fact that by default, they consider any new window to be opened as a SPAM. For example, whenever I go to ESPN to check sports results, I always have this big Orbitz advertising window which takes about the entire width in 1024 resolution and about 1/3 in height. This has been the case since a few months. I understand this is probably the biggest advertising vendor at ESPN and they are paying big money to benefit of that, but it is getting extremely annoying for users.

You go to a Web site that already has enough advertisements in the base window, so, why would you want to receive more in a new window that you will probably close right away as you wish to gain access to the sports results as fast as you can.

For big companies that already rely on another structure to bring money in, it is more frustrating that they are using such practice online as well. And, this is used widely by many companies across the Internet. The bigger their company, the bigger the amount of advertisement you will receive when navigating to their Web site.

But, not all new opened windows are advertisement. And, this is where the big problem is. You build a desktop application, have an invoicing form to build the invoice, and the first field the user has to select is the client ID. To collect the client ID, the user will probably click on an icon next to the field to launch a pick list. He selects a client by searching for it, sorting and filtering and now has the client ID in the base form. Why the same approach would be bad on the Internet? It isn't. But, the perception of those who builds such tools are creating a perception which auto-defaults to remove any new opened window to be disabled when the related no advertisement option is turned on.

Here is a new window that we are opening on the Universal Thread for selecting a member:

So, as you can see, this is totally not related to an advertisement. It is a pick list used to select a member and probably the best approach you could use for the related need.

But, for users using a tool which allows them to disable new windows, this creates a scenario, when this setting is turned on, that the user will click on a specific link on your site and nothing will ever happen. So, the user, in most cases, will think your Web site is not properly working. In many scenarios, he will not contact you assuming it would be fix soon. But, after having been frustrated at several occasions, you will then receive an email. The situation would be adjusted as to user, making use of such tool, can usually apply a filtering setting in order to have this new windows to work on your site.

The following are popular tools which support such ability:

  • AdSubtract
  • Norton Internet Security
  • Zone Alarm
Those tools will allow you to enable such option but also to filter on specific Web sites. So, you can have it turned on but, for specific Web sites, it will not apply. Under Norton Internet Security, this is known as "Turn on Window Popup Blocking" under the "Ad blocking" option. You should be able to find your way in their for full customization to fit your own needs.

So, again, a proper documentation on your Web site will help so is any additional ways of letting your users know about that requirement.

Michel Fournier, Level Extreme Inc.
Michel Fournier is a professional, visionary, perfectionist, mostly known for his renowned realizations over the years, designer, architect, owner of the « Level Extreme Platform », formerly known as the « Universal Thread », recognized as one of the longest running Web sites of the planet, also known as a precursor to social networking, product manager, Internet serial entrepreneur, practiced Lean Startup techniques long before they were known, out of the box thinker, using the tenth man rule, specializes in building entire virtual data center solutions, has provided high end IT consulting worldwide, has owned and operated three companies, delivered worldwide renowned e-commerce Web sites, designed and architected two world class top level development frameworks, wrote over 100 IT articles for various sources, presented at user groups, conventions and corporations nationwide as well as in the US, has provided his contribution in political and legal issues to provide a better world, Owner and Senior IT Consultant at Level Extreme Inc., former Architect Software/Application & Project Manager, 7 times Microsoft Most Valued Professional for VB.NET, 7 times Microsoft Most Valued Professional for Visual FoxPro, Developers Choice award for best site at VFP DevCon 2000 Connections in New Orleans, featured in Acadie Nouvelle on October 2003.
More articles from this author
Michel Fournier, February 1, 2007
From the Level Extreme .NET Framework, this small class allows a developer to manipulate easily the content of a directory by the use of a dataset. With the setup of a few properties, a call to the method and the access to the object dataset, you can have access to the file properties of the directo...
Michel Fournier, August 1, 2001
It is interesting to see how something new can evolve. This is the case for the Universal Thread Magazine. We are now at our 3rd issue and we are already overbooked by scheduled articles and hot stuff we have to cover for the upcoming issues. Publishers are sending request for book reviews, wri...
Michel Fournier, October 1, 2002
UTMag/RapoZine team Editors Michel Fournier Claudio Lassala Co-editor Martín Salías Translation coordinators Claudio Lassala Martín Salías Translators Eduardo Vidigal Rodolfo Duarte Fábio Vazquez José Cavalcanti Moacyr Zalcman Fábio Vieira M...
Michel Fournier, May 1, 2006
In this article, Michel Fournier is providing a small introduction to manipulating XML data from VB.NET. The use of XML is now widely used for various purposes such as exchanging data between application, platforms and other environments. XML is a simple and very flexibile text format that can be ma...
Michel Fournier, October 1, 2001
In our daily things we do, sometimes we find ourselves in unexpected situations. Such situations, either in our personal life or from our professional work, require some adjustments in order to walk through them. The ability to take some time to take an overall look of what is happening, apply a bas...
Michel Fournier, March 1, 2007
In this small article, Michel discusses a problem he recently encountered when converting a dataset into XML to be used later on with a XSL transformation to export into an Excel sheet. When null values were present in the dataset, this was creating weird result. This article provides a quite alte...
Michel Fournier, February 1, 2006
This article discusses a simple banner fonctionalities function which can ease the display of banners on Web sites. If your Web site displays banners in GIF, JPG of Flash format, this function could be useful to you.
Michel Fournier, January 1, 2006
There are various ways to authenticate a user to a Web Service. This article discusses one way to do it by the use of Cookies. As it could the case with a Web page sending a cookie to the browser, the same can be used from within a Web Service.
Michel Fournier, February 1, 2006
This article is a follow up on the first part of this article which appeared on our January 2006 issue. In this one, Michel discussed further implementation of getting the authentication from a members table as well as setting up a session per user.
Michel Fournier, December 1, 2003
Visual FoxPro and .NET are two great environments to build business applications with. But, fantastic they are when you combine them together in order to increase the strenght of the flexibility to respond to your client needs. In this article, I will demonstrate a case study in regards to a new ser...
Michel Fournier, December 1, 2002
Over the years, I have been involved in several types of desktop and Web applications. Every time you start a new project, there is always something new you will learn. In this article, I would like to detail some of the issues which are to be considered when delivering a Web based application. Thos...
Michel Fournier, January 1, 2003
This article is a follow-up with more advanced details in regards to the first article of this series in our December issue which included a tip on dealing with stylesheets. This one allows you to customize your HTML code based on the user, assuming each user has some ways to setup some specific sty...
Michel Fournier, March 1, 2003
The first two articles of this series have been published in the issues of December 2002 and January 2003. In this one, I will talk about graphic issues, how to negotiate with a form to launch his transaction to either within the same window or a new one, how to gather values from one page to anothe...
Michel Fournier, April 1, 2009
This articles describes the use of CDO.Message to gain the ability to retrieve a URL as a MHT file. It also covers an interesting approach to retrieve a URL even if this one requires a login.
Michel Fournier, January 1, 2006
Data dictionaries has its use and also for Web applications. I see many developers building Web applications who forget about many structured that used to be in place when developping desktop applications. The same should apply for Web applications as it is no different. This article discusses some ...
Michel Fournier, June 1, 2003
DevTeach was held in Montreal from May 10-13, 2003. It presented a new breed of conference. Sessions included both presentation material and, whenever possible, hands-on training. DevTeach brought under the same roof the best speakers available for .NET, SQL Server and Visual FoxPro as well as Micro...
Michel Fournier, May 1, 2002
The Essential Fox conference was held this weekend in Independence, MO. Once again, the Universal Thread team was on site to do the official coverage of the event. It has been a great success, well planned by Russ Swall, the event owner, and his team and well appreciated by the attendees. A total of...
Michel Fournier, April 1, 2002
UTMag/RapoZine team Editors Michel Fournier Claudio Lassala Translation coordinators Claudio Lassala Martín Salías Translators Eduardo Vidigal Rodolfo Duarte Fábio Vazquez Claudio Rola José Cavalcanti Moacyr Zalcman Ricardo Soares Fábio Vieira ...
Michel Fournier, September 1, 2001
Ever wonder how to successfully and rapidly display HTML lists to your users? Well, we all probably already did. However, its implementation differs a lot from sites to sites as we all have our own different approaches. Delivering Visual FoxPro data to the Web as if you would be in Visual FoxPro is ...
Michel Fournier, November 1, 2001
A lot of things happened recently in the Visual FoxPro world and for related technologies. The Great Lakes Great Database Workshop was being held in Milwaukee from Sunday October 27 to Wednesday October 31. That conference which primaly focused on Visual FoxPro has covered a lot of technologies...
Michel Fournier, December 1, 2002
UTMag/RapoZine team Editors Michel Fournier Claudio Lassala Co-editor Martín Salías Translation coordinators Claudio Lassala Martín Salías Translators Eduardo Vidigal Rodolfo Duarte Fábio Vazquez José Cavalcanti Moacyr Zalcman Fábio Vieira M...
Michel Fournier, November 1, 2002
UTMag/RapoZine team Editors Michel Fournier Claudio Lassala Co-editor Martín Salías Translation coordinators Claudio Lassala Martín Salías Translators Eduardo Vidigal Rodolfo Duarte Fábio Vazquez José Cavalcanti Moacyr Zalcman Fábio Vieira M...
Michel Fournier, January 1, 2003
UTMag/RapoZine team Editors Michel Fournier Claudio Lassala Co-editor Martín Salías Translation coordinators Claudio Lassala Martín Salías Translators Rodolfo Duarte Fábio Vazquez Moacyr Zalcman Martín Salías Antonio Castaño Fabián Belo Rafae...
Michel Fournier, November 1, 2001
I have been following several threads on the Universal Thread recently about FTP from Visual FoxPro. I have used an ActiveX for a while to do such a task. I have found that years after years, the problem is that you have to maintain that ActiveX for your own workstation and for every servers or work...
Michel Fournier, July 1, 2002
UTMag/RapoZine team Editors Michel Fournier Claudio Lassala Co-editor Martín Salías Translation coordinators Claudio Lassala Martín Salías Translators Eduardo Vidigal Rodolfo Duarte Fábio Vazquez José Cavalcanti Moacyr Zalcman Fábio Vieira M...
Michel Fournier, January 1, 2006
With the beginning of the new year, Michel resumes some of the highlights of the Universal Thread and what is coming up for the new season.
Michel Fournier, March 1, 2006
When comes time to display the content of a memo field on a Web page, one common task we have to do is to hyperlink specific content. This article discusses about a technique which can be used to hyperlink various types of links as well as email addresses.
Michel Fournier, April 1, 2009
This article describes some basic techniques to manipulate some images in .NET. It covers image resizing, image cropping and the ability to save an image into a JPG high resolution format.
Michel Fournier, May 1, 2007
This short articles provides an approach of important data from an Excel sheet into your application without having the requirement of having Excel installed on the server.
Michel Fournier, August 1, 2002
UTMag/RapoZine team Editors Michel Fournier Claudio Lassala Co-editor Martín Salías Translation coordinators Claudio Lassala Martín Salías Translators Eduardo Vidigal Rodolfo Duarte Fábio Vazquez José Cavalcanti Moacyr Zalcman Fábio Vieira M...
Michel Fournier, July 1, 2001
Recently, I was having problems while working on several projects on my PC. The problems were happening when I had several applications open at the same time. When the problem occured, I had to reboot my PC and then was able to work for a few hours up to a few days until the next reboot. As I was wo...
Michel Fournier, June 1, 2002
UTMag/RapoZine team Editors Michel Fournier Claudio Lassala Co-editor Martín Salías Translation coordinators Claudio Lassala Martín Salías Translators Eduardo Vidigal Rodolfo Duarte Fábio Vazquez José Cavalcanti Moacyr Zalcman Fábio Vieira M...
Michel Fournier, September 1, 2002
UTMag/RapoZine team Editors Michel Fournier Claudio Lassala Co-editor Martín Salías Translation coordinators Claudio Lassala Martín Salías Translators Eduardo Vidigal Rodolfo Duarte Fábio Vazquez José Cavalcanti Moacyr Zalcman Fábio Vieira M...
Michel Fournier, January 1, 2001
Xitech (Europe) produces tools for the Windows software developer. They specialize in FoxPro Developer tools, data and code recovery and security. In this article, we will see an overview of 5 of their tools. You will find more details about each of them from Xitech documentation. To get Xitech cont...
Michel Fournier, April 1, 2006
This article discusses the ability to use Visual FoxPro to schedule a list of tasks to be executed at specific intervals. While there could be the approach of using the Windows Scheduler to execute those tasks, it is always interesting to be able to control everything from within VFP. A small VFP sc...
Michel Fournier, April 1, 2006
This article describes an overview of sending an email from VB.NET. It covers the basis of creating the email functionality in a class and using an instance of that class to define and send the email. The class includes the ability to send to multiple recipients as well as sending attachments. Sendi...
Michel Fournier, July 1, 2002
This is a follow up on my previous article on using SOAP protocol for authentication that appeared in our December 2001 issue. That article was mentioning the use of the SOAP header for authentication such as being able to identify the user for any upcoming hit to your Web Service as soon as the Log...
Michel Fournier, May 1, 2002
UTMag/RapoZine team Editors Michel Fournier Claudio Lassala Translation coordinators Claudio Lassala Martín Salías Translators Eduardo Vidigal Rodolfo Duarte Fábio Vazquez José Cavalcanti Moacyr Zalcman Fábio Vieira Martín Salías Antonio Castañ...
Michel Fournier, July 1, 2002
From recent discussions I had, with several persons from my team, about common patterns which occur in the evolution of the Universal Thread, I thought it would be nice to write an article about it. Basically, within the evolution of a product, there are some similitudes which are sometimes interest...
Michel Fournier, June 1, 2001
Welcome to our first issue of the Universal Thread Magazine. We kept receiving many requests to have such a media available on the Universal Thread, so we decided to release our first issue this month. Many people have mentioned an interest to either have such a magazine for the pleasure to read abo...
Michel Fournier, December 1, 2001
The Visual FoxPro Zone evolves As many of you may have seen, the Universal Thread Visual FoxPro Zone is evolving quite fast. In the last month, we added new content in it. As usual, the most popular option is the Toledo Wish List. Several entries are created every day. This is the place to co...
Michel Fournier, January 1, 2002
It's January 3rd, 2002, I am writing this editorial at 20h32 EST. The Christmas break is over but was it really a break? More and more, years after years, I keep seeing a lot of persons online during Christmas day or a few minutes before the new year. And, I mean, they are online as per their own ti...
Michel Fournier, January 1, 2004
In December 1993, a great history started when a small Web site known as the Visual FoxPro Yellow Pages started. Basically, a site providing ads for Visual FoxPro developers such as jobs and consulting services. Known also as the first Visual FoxPro site, it has evolved quite fast during the first t...
Michel Fournier, January 1, 2006
In the recent months, I have been involved in settings various projects at client sites, as well as for Level Extreme Web sites, which involved the support of uploading image files from an Internet browser. The process of supporting that capability in your application, either from a desktop of from ...
Michel Fournier, December 1, 2001
The Microsoft SOAP client provides access to any Web Service. Once the object is instantiated and the location of the WSDL file given, you are ready to go to access any method. Thus, based on what is supported by the Web Service, you can query to obtain various types of content such as string and bo...
Michel Fournier, February 1, 2002
On January 15th, 2002, an important joint took place for our magazine. The Universal Thread Magazine and RapoZine magazine, an online magazine available for the Portuguese developers community, joined to create UTMag/RapoZine. Effective from this issue, both magazines will offer the same technical c...
Michel Fournier, July 1, 2002
Show seconds in a readable format If you need to check elapsed time with seconds() or a datetime value, this function allows you to display the elapsed time in a human-readable format, that is, hours:minutes:seconds, instead of the total number of seconds. Just pass a number of seconds as...
Michel Fournier, August 1, 2002
Updating your DLL on IIS This has been a common question in the recent months on the Universal Thread. More and more, developers have the need to use a DLL under IIS. However, the fun part comes when you need to update it. As soon as it kicks in, you can't update your DLL anymore as it re...
Michel Fournier, November 1, 2002
Use MemLines() to wrap text lines When you need to wrap some text at a given width (say 75 characters per line), you do it easily with: SET MEMOWIDTH TO 75 lcMemo = lcNewMemo = "" _MLINE = 0 FOR i= 1 TO memlines(lcMemo) lcNewMemo = lcNewMemo ; + MLINE(lcMemo,1,_MLINE...
Michel Fournier, September 1, 2002
Getting image width and height Probably the most flexible way to extract the width and height of an image is by the use of the image object. All is needed is to load the image in the object and get the values from the Width and Height properties. LOCAL loImage,lnWidth,lnHeight loIma...
Michel Fournier, October 1, 2002
Extracting BMPs from general fields As a complement with last issue's article on image handling, yo can find useful this little function. If you got convinced that using general fields to handle images is a bad idea, you can decided go back to independent image files. But then you'll...
Michel Fournier, June 1, 2001
It was a year ago. The DevConnections team was holding the Visual FoxPro DevCon 2000, the SQL Server Connections and the DevCon 2000 in New Orleans, Louisiana from May 14 to 18, 2000. For the first time, attendees were able to attend sessions from more than one conference at the same time. This offe...
Michel Fournier, September 1, 2001
Is there a speed limit on the Internet? Probably not, because there is so much things we can do in a short time about delivering various type of content to the community. I remember a week ago we shared an idea about helping the promotion of user group activities around the world. A week ago it was ...
Michel Fournier, March 1, 2002
In the last month, we received dozens of emails from satisfied persons in regards for our initiative of opening the magazine and the Universal Thread in general for additional communities such as the Portuguese and Spanish communities. Regulars members of the Universal Thread, new members, Microsoft...