    Vijay Patel Guest

    I have my application running at http://someserver/someapp. In normal execution path user can go to http://someserver/someapp/some.asp . But user can directly to that URL there by typing whole URL and bypassing all authentication. Please let me know how we can prevent user going directly to that URL. <BR><BR>Thanks<BR>Vijay

    Ashish Mishra Guest

    You can define a session variable which is initialized in the session_onstart event and then each time the user accesses any other page other than the logon screen, you check that session variable, if it is empty, dont just allow the user to access that page. Define this session variable in the global.asa file.<BR>Simple isnt it.

