Knowledge Base

Wininet Credentials Are Not Reset on Keep-Alive Connections

Article ID: 195567

Article Last Modified on 1/23/2007


APPLIES TO


This article was previously published under Q195567

SYMPTOMS

The Wininet InternetSetOption API call can be used to modify the credentials used for a HTTP request. However, if a previous successfully authenticated keep-alive connection has already been made with the server, Wininet continues to use the old credentials.

RESOLUTION

To resolve this problem, obtain and install Internet Explorer 4.01 Service Pack 2. You can obtain Internet Explorer 4.01 Service Pack 2 from the following Microsoft Web site:


STATUS

Microsoft has confirmed this to be a problem in the products listed at the beginning of this article.

MORE INFORMATION

The following example demonstrates the problem described in this article:

  1. Successful request using User, Password credentials: hOpen = InternetOpen(...) hConnect = InternetConnect ( hOpen,"Server", ..., User , password , INTERNET_SERVICE_HTTP,...) hReq = HttpOpenRequest (hConnect, "GET", Url , ...) HttpSendRequest (hReq, ...) InternetReadFile(hReq, ...)
  2. Modify the credentials using: InternetSetOption (..., INTERNET_OPTION_USERNAME , User2...) InternetSetOption (..., - INTERNET_OPTION_PASSWORD, Password2,...)
  3. The new request still uses User, Password credentials: hReq = HttpOpenRequest (hConnect, "GET", Url , ...) HttpSendRequest (hReq, ...) InternetReadFile(hReq, ...)
The fix detects if the credentials have been changed on a new request.

Keywords: kbqfe kbnetwork kbprb kbhotfixserver KB195567