Tuesday, August 28, 2007

Continuous integration [CI]

“Continuous Integration is a software development practice where members of a team integrate their work frequently, usually each person integrates at least daily - leading to multiple integrations per day. Each integration is verified by an automated build (including test) to detect integration errors as quickly as possible. Many teams find that this approach leads to significantly reduced integration problems and allows a team to develop cohesive software more rapidly. This article is a quick overview of Continuous Integration summarizing the technique and its current usage.” (Martin Fowler)

Here is a picture from (http://confluence.public.thoughtworks.org/display/CCNET/CruiseControl.NET+Integration+Process):


References

Thursday, February 01, 2007

Security Measures to take into account when designing web sites

  • Always create at least two network boundaries:
    1. A DMZ (i.e. Front-end machine area)
      • Web servers mainly, but it could have other machines used for communication, as long as:
        • No customer data should be hold in this network boundary
        • Machines in this boundary can only talk to machine on the next level down if that machine does not hold any confidential data (e.g. Customer Data, Partners data, Employees data, etc..)
    2. A Back-end machine area
      • Application servers
      • Database servers containing confidential data migh be here (or a third boundary network could host them)
      • Intranet web servers
      • dqw
  • A firewall must exits:
    • In front of the DMZ
    • Between the DMZ and the back-end area
  • Machines in the F-E can trust machines in the B-E
  • Machines in the B-E cannot trust machines/identities from the F-E
  • If an Employee or Partner Web site must be available from the Internet area, it must be in a different DMZ (if possible).
  • It is always a good thing to have two URLs for a web site:
    1. http://www.mysite.com/ for normal browsing (port 80)
    2. https://secure.mysite.com/ for secure browsing (port 443)
      • This enables HTTPS to be handled by hardware
      • The Encryption traffic will happen between the client’s browser and the public firewall in front of the DMZ
      • In the DMZ, the HTTP request can be handled by the normal HTTP port (80). The application can still check whether this is a secure HTTP request by looking at the domain (http://www.mysite.com/ or secure.mysite.com).

Monday, January 15, 2007

HTTP Request issues – "Expect: 100-continue" and "Connection: Keep-Alive" headers


I have been working on a little .NET application (1.1) tool to send other HTTP the content from an XML file.

As I was intercepting the HTTP requests/responses going on between my machine and the server, I found out that my .NET application was always sending as part of the headers:

  • "Expect: 100-continue"
  • "Connection: Keep-Alive"

My application will always send a HTTP request in one go, get the response and exit. So, I need to get rid of those two HTTP headers (or at least disable them).

Here a sample from “TCPTrace”:
# The HTTP request


POST /HTTPFlowerServer/Cancellation.aspx HTTP/1.1
Content-Type: text/xml
Content-Length: 89
Expect: 100-continue
Connection: Keep-Alive

Host: localhost:8080

<?xml version='1.0' encoding='utf-8'?>
<MyRequest><Cancellation Id="27" /></MyRequest>


# The HTTP response


HTTP/1.1 100 Continue

HTTP/1.1 200 OK
Date: Mon, 15 Jan 2007 18:23:03 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=sq2f2p55jqjluojh3mr4qh3o; path=/
Cache-Control: private
Content-Type: text/xml; charset=utf-8
Content-Length: 74

<MyResponse><Acknowledgement OrderId="27"></Acknowledgement></MyResponse>


In order to not keep the connection alive, you need change the “KeepAlive” property of your HttpWebRequest.

In order to remove the “Expect: 100-continue”, you need to change the settings on the ServicePoint used by your request.

Here is what you need to do:


HttpWebRequest myRequest = (HttpWebRequest)System.Net.WebRequest.CreateDefault(targetURI);
myRequest.Method = "POST";
myRequest.KeepAlive = false;
myRequest.ServicePoint.Expect100Continue = false;


I found the latter solution from a blog at http://haacked.com/archive/2004/05/15/449.aspx. Look for the entry made by Mirronelli.

Here a sample of the HTTP headers after the changes:

# The HTTP request


POST /HTTPFlowerServer/Cancellation.aspx HTTP/1.1
Content-Type: text/xml
Content-Length: 89
Connection: Close
Host: localhost:8080

<?xml version='1.0' encoding='utf-8'?> <MyRequest><Cancellation Id="27" /></MyRequest>

# The HTTP response


HTTP/1.1 200 OK
Connection: close
Date: Mon, 15 Jan 2007 19:00:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=npxysrbhbz4rsi455x5qhe45; path=/
Cache-Control: private
Content-Type: text/xml; charset=utf-8
Content-Length: 74

<MyResponse><Acknowledgement OrderId="27"></Acknowledgement></MyResponse>