  #1
    Join Date
    Dec 1969

    Login pages

    I have used a database driven login script(I found on 4guys) to add security to a small project that I am in the stages of completing. The login works okay. However, I have a few things that I need help with.<BR>1. There will only be a limited number of users allowed to access the<BR>site(login page) anyway, and it would be a waste checking all of the<BR>users everytime, is there any way to avoid having to do this.<BR>2. The secure page can still be copied and pasted. How can I avoid<BR>this?<BR><BR>AS regards the layout here it is:<BR>inter.asp- this is the form for logging in<BR>register.asp- this is the processing page which is sent the form from inter.asp<BR>add_to_db.asp- this is the secure page that I am trying to lock<BR>access to those who have successfully logged in from inter.asp.<BR>I have placed the bit of script at the top of add_to_db.asp as I was directed by the author but this seems to make no difference as it can still be copied(url) and pasted and it still allows access.<BR>Can anyone help?<BR>Thanx<BR>Lucy

  #2
    Mark Parter

    RE: Login pages

    I use a Session variable on my login pages. On the register.asp page, if the user is allowed access then you can set the value of this variable as 1. <BR>e.g. Session("Authenticated") = 1<BR><BR>Create a new file called &#039checkuser.inc&#039 then put this code into it:<BR><BR>&#060;% If Session("Authenticated") = 0 Then<BR> Response.Redirect "inter.asp"<BR>End If %&#062;<BR><BR>Then at the top of every page that you want to protect you would put a reference to this file, like so:<BR><BR>&#060;!--#INCLUDE FILE="checkuser.inc"--&#062;<BR><BR>Hope this helps

  #3
    al dawg

    RE: Login pages

    another way is to be sure that the user comes from register.asp by checking to see if it&#039s the referring page. if it&#039s not, then redirect the secure page back to the login.<BR>

