URL Based Authorization With Authenticated Users

by Bill Beckelman 5/12/2008 9:32:00 PM

I have had an issue with one of my projects for some time that really confuses users especially on shared computers. What generally happens is a user with proper credentials logs out but leaves the browser open so when the next user enters their credentials the site tries to send them to the page that the first user last viewed before logging out. When the second user is not authorized to view the page, he is redirected to the login page again. The user then tries to enter his credentials again and again and cannot access the site. This can also happen when one user sends a link to another user who is authorized to view the site, but not the page that is linked to.

I ran across an article by Scott Mitchell that solves this very problem by directing the users to a page that explains they are not authorized to view the requested page instead of sending them to the login page. Scott presents a quick and easy fix in step 2 of his article as well as plenty of additional valuable information: http://asp.net/learn/security/tutorial-07-cs.aspx.

Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Tags:

ASP.NET

Related posts

Add comment


(Will show your Gravatar icon)  

  Country flag

[b][/b] - [i][/i] - [u][/u]- [quote][/quote]



Live preview

7/3/2008 4:43:45 PM



Powered by BlogEngine.NET 1.3.0.29
Theme by Mads Kristensen

About the author

Name of author Bill Beckelman
I live and work in South Jordan, Utah

E-mail me Send mail

Calendar

<<  July 2008  >>
MoTuWeThFrSaSu
30123456
78910111213
14151617181920
21222324252627
28293031123
45678910

View posts in large calendar

Pages

    Recent comments

    Disclaimer

    The opinions expressed herein are my own personal opinions and do not represent my employer's view in anyway.

    © Copyright 2008

    Sign in