PHP Development
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
 
Go Back   Dev Articles Community ForumsProgrammingPHP Development

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Display Modes
 
Unread Dev Articles Community Forums Sponsor:
  #1  
Old January 26th, 2005, 11:41 AM
daidalus13 daidalus13 is offline
Registered User
Dev Articles Newbie (0 - 499 posts)
 
Join Date: Jul 2004
Posts: 16 daidalus13 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 12 m 51 sec
Reputation Power: 0
Authentication using sessions: Problem - back button re-authenticates users

Hi, That's a problem I have.


I am authenticating my users against userid/password combinations kept in a MySQL database. When a user is authenticated, a session starts. When the users signs out, I destroy the session. So, the sessionid is deleted and any future request coming with this sessionid is treated as a security threat and the user receives my “non-authorised” page.

However:

If someone starts pressing the back button on that client’s machine, eventually the login page will comeup from the history. The user will prompted with the usual message “repost data?”. Thus, the userid/password combination is reposted and the user is authenticated! However, now I am not sure that the person sitting on the client machine is actually the same user that entered the correct userid/password in the first place.



How do I solve this?


Any ideas greatly appreciated. No need for code. Just give me some ideas.

Thanks
Daidalus13

Last edited by daidalus13 : February 7th, 2005 at 02:04 PM. Reason: make title more precise

Reply With Quote
Reply

Viewing: Dev Articles Community ForumsProgrammingPHP Development > Problme: Back button re-authenticates user


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway
Stay green...Green IT