    homebody

    i want my web page check to see if the user has been authenticated -- if not, send him to page A and if so, to page B. this is the code i&#039;m using:<BR><BR>&#060;% @Language=VBScript %&#062;<BR>&#060;% if Request.ServerVariables("AUTH_USER") = null then%&#062;<BR> &#060;a href=;<BR>&#060;% else %&#062;<BR> &#060;a href=;<BR>&#060;% end if %&#062;<BR><BR>this always sends me to already_auth.asp, even if the user has not yet been authenticated. i have also tried <BR> &#060;% if Request.ServerVariables("AUTH_USER") = "" then%&#062;<BR>and this always sends me to authenticate.asp, even if the user has already been authenticated.<BR><BR>my web server is iis 4.0, and i&#039;m using basic authentication with ssl.<BR><BR>what am i missing? thanks!

    I&#039;m not familiar with Auth_user<BR>do you mean Request.ServerVariables("LOGON_USER") ?<BR><BR>Jay

    homebody

    it is my understanding that LOGON_USER is the user logged on to the client machine, while AUTH_USER is the user that has been authenticated on the web server through iis basic authentication. i know that AUTH_USER is a valid session variable -- see i can display the contents of AUTH_USER and it is always what i expect it to be -- the authenticated username or (seemingly) blank.<BR><BR>but there&#039;s obviously SOMETHING that&#039;s not working how i think it should be or i wouldn&#039;t be here, huh? :)<BR><BR>

    homebody

    it appears that LOGON_USER does the same thing as AUTH_USER in my situation. microsoft says that AUTH_USER is the "raw authenticated username" and LOGON_USER is "the windows account that the user is logged into" ... just fyi. both give me the same problem with determining whether the user has been authenticated yet or not.

    homebody

    it wasn&#039;t that the value wasn&#039;t being read correctly. the code i send was in a frame. the <BR> string = "" <BR>was reading everything correctly. but what i was trying to do was to refresh that frame after being authenticated in another, assuming that it would pick up the newly acquired AUTH_USER information -- it wasn&#039;t. <BR><BR>now i can start looking for how to get around THIS!

