<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.asp.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security</title><link>http://forums.asp.net/25.aspx</link><description>All about ASP.NET security (authentication, authorization, membership, roles, etc.) and the Login controls. &lt;a href="http://aspadvice.com/SignUp/list.aspx?l=24&amp;c=17" target="_blank"&gt;Email List&lt;/a&gt;</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Re: Problem Logging out using LoginStatus Control or FormsAuthentication.SignOut()</title><link>http://forums.asp.net/thread/3254916.aspx</link><pubDate>Wed, 24 Jun 2009 09:44:48 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3254916</guid><dc:creator>anshivank</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3254916.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=3254916</wfw:commentRss><description>&lt;p&gt;yes this is a good solution to back button problem...but what i have found out is that even if we write the middle line of the code you have given i.e. &lt;span style="FONT-WEIGHT:bold;"&gt;Response.Cache.SetCacheability(HttpCacheability.NoCache); &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-WEIGHT:bold;"&gt;even then it will work. My question is.. what is the need of writing extra code i.e. first and the last line of your code.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-WEIGHT:bold;"&gt;Thanx in advance&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-WEIGHT:bold;"&gt;shivank&lt;/span&gt;&lt;/p&gt;</description></item><item><title>Re: Problem Logging out using LoginStatus Control or FormsAuthentication.SignOut()</title><link>http://forums.asp.net/thread/3218263.aspx</link><pubDate>Mon, 08 Jun 2009 17:33:31 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3218263</guid><dc:creator>klpatil</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3218263.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=3218263</wfw:commentRss><description>yippee!!! Congrats Man!! &lt;img src="http://forums.asp.net/emoticons/emotion-19.gif" alt="Party!!!" /&gt;</description></item><item><title>Re: Problem Logging out using LoginStatus Control or FormsAuthentication.SignOut()</title><link>http://forums.asp.net/thread/3217926.aspx</link><pubDate>Mon, 08 Jun 2009 14:42:56 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3217926</guid><dc:creator>miniGweek</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3217926.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=3217926</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Hello Kiran ,&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;My Problem is solved ! Thank you so much for guiding me in the right direction.&amp;nbsp;&lt;/p&gt;&lt;p&gt;I used a master page , and included the code you mentioned in the Page_Load() . And the rest of the pages I derived from the master page , and its working like a charm.&lt;/p&gt;&lt;p&gt;Now , neither the back button&amp;nbsp; or Manually typing in the url takes me those page , they redirect to me to login page as it should.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Thanks and Regards&lt;/p&gt;&lt;p&gt;- Rahul &lt;br /&gt;&lt;/p&gt;</description></item><item><title>Re: Problem Logging out using LoginStatus Control or FormsAuthentication.SignOut()</title><link>http://forums.asp.net/thread/3217338.aspx</link><pubDate>Mon, 08 Jun 2009 09:47:47 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3217338</guid><dc:creator>klpatil</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3217338.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=3217338</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Hi,&lt;/p&gt;&lt;p&gt;Thanks for the nice words!!&lt;/p&gt;&lt;p&gt;Sorry, i have updated the forums link and i am eagerly waiting for your reply..&lt;br /&gt;&lt;/p&gt;</description></item><item><title>Re: Problem Logging out using LoginStatus Control or FormsAuthentication.SignOut()</title><link>http://forums.asp.net/thread/3217215.aspx</link><pubDate>Mon, 08 Jun 2009 08:41:11 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3217215</guid><dc:creator>miniGweek</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3217215.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=3217215</wfw:commentRss><description>&lt;p&gt;Hello Kiran ,
&lt;/p&gt;&lt;p&gt;Your input is much&amp;nbsp; appreciated. Thanks a lot for explaining the problem , and giving me the code project link. Though the forums.asp.net link seems dead. Anyways , I will try out your suggestion and come back.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Have a good day .&lt;/p&gt;&lt;p&gt;Regards&lt;/p&gt;&lt;p&gt;- Rahul &lt;br /&gt;&lt;/p&gt;</description></item><item><title>Re: Problem Logging out using LoginStatus Control or FormsAuthentication.SignOut()</title><link>http://forums.asp.net/thread/3216636.aspx</link><pubDate>Mon, 08 Jun 2009 02:52:21 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3216636</guid><dc:creator>klpatil</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3216636.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=3216636</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Hi Dear,&lt;/p&gt;&lt;p&gt;Sorry for inconveniences caused to you for this problem..it is because of Client side caching..And i hope that you are clear with how all the things work in background means forumauthentication and all that..if not give me a shout will be glad to help you..alrighty let&amp;#39;s come to the point:&lt;/p&gt;&lt;p style="font-weight:bold;"&gt;you can try this to put in your pages: Page_Load - which you don&amp;#39;t want to be cached by client side:&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-weight:bold;"&gt;Response.Cache.SetExpires(DateTime.UtcNow.AddMinutes(-1));&lt;/span&gt;&lt;br style="font-weight:bold;" /&gt;&lt;span style="font-weight:bold;"&gt;Response.Cache.SetCacheability(HttpCacheability.NoCache);&lt;/span&gt;&lt;br style="font-weight:bold;" /&gt;&lt;span style="font-weight:bold;"&gt;Response.Cache.SetNoStore();&lt;/span&gt; &lt;br /&gt;&lt;/p&gt;&lt;p style="font-style:italic;"&gt;//NOTE: Rather than adding to all pages..i suggest you you to create one BasePage which dervice from Page Class and all your pages should derive from this BasePage and the above code you can put it in your BasePage&amp;#39;s Page_Load...hooh it is Oops &amp;quot;Reusability&amp;quot; :)&lt;/p&gt;&lt;p style="text-decoration:underline;"&gt;&lt;span style="font-weight:bold;"&gt;You can refer more links here :&lt;/span&gt; &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.codeproject.com/KB/aspnet/NoCaching.aspx"&gt;http://www.codeproject.com/KB/aspnet/NoCaching.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://forums.asp.net/p/1422862/3161876.aspx"&gt;http://forums.asp.net/p/1422862/3161876.aspx &lt;/a&gt;&lt;/p&gt;&lt;p&gt;We refer this problem as a &amp;quot;Back Button problem&amp;quot;.&lt;/p&gt;&lt;p&gt;Keep me posted on the same if it works or not :)&lt;/p&gt;&lt;p&gt;Programming is Fun!!!&lt;br /&gt;&lt;/p&gt;</description></item><item><title>Problem Logging out using LoginStatus Control or FormsAuthentication.SignOut()</title><link>http://forums.asp.net/thread/3216474.aspx</link><pubDate>Sun, 07 Jun 2009 22:56:47 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3216474</guid><dc:creator>miniGweek</dc:creator><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3216474.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=3216474</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Hello there fellas ...&lt;br /&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;br /&gt;I seem to have run into a problem , and no amount of Google Trolling or forum digging at many places seem to get me a solution.&amp;nbsp;&lt;img src="http://forums.asp.net/emoticons/emotion-9.gif" alt="Crying" /&gt; Really feels like crap&amp;nbsp;&lt;img src="http://forums.asp.net/emoticons/emotion-6.gif" alt="Sad" /&gt; Thus my desperate attempt at some form of help from you people here .. &lt;br /&gt;&lt;br /&gt;Now that I have expressed my frustration, anger and what not , I will get on with the &lt;b&gt;Whats&lt;/b&gt; actually making my life difficult. &lt;img src="http://forums.asp.net/emoticons/emotion-42.gif" alt="Confused" /&gt;&lt;/p&gt;&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;br /&gt;------------------------------------&lt;i&gt;end of rant&lt;/i&gt;------------------------------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I am trying to implement security for an already existing website. I am using ASP.NET along with Visual Studio 2005 for the purpose.&amp;nbsp; After going through books like :&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;b&gt;Apress.Pro.ASP.NET.2.0.in.C.Sharp.2005&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Sams.ASP.NET.3.5.Unleashed&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;For.Dummies.ASP.NET.2.0.All.In.One.Desk.Reference.For.Dummies&lt;/b&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;br /&gt;I thought I had pretty good grasp on what is and what nots of Authentication and Authorization using ASP.NET . Apparently not ! :cryinganime:&lt;br /&gt;&lt;br /&gt;I am using &lt;b&gt;Forms Authentication&lt;/b&gt; and &lt;b&gt;Credentials Store&lt;/b&gt; in Web Config file to store the username and password. Following is how the authentication and authorization of my web config file looks like :-&lt;br /&gt;&lt;/p&gt;&amp;nbsp;&lt;pre class="coloredcode"&gt;&amp;lt;authentication mode=&amp;quot;Forms&amp;quot;&amp;gt;&lt;br /&gt;      &amp;lt;&lt;span class="tag"&gt;forms&lt;/span&gt;&lt;span class="attr"&gt; loginUrl=&lt;/span&gt;&lt;span class="attrv"&gt;&amp;quot;~/Default.aspx&amp;quot;&lt;/span&gt;&lt;span class="attr"&gt; protection=&lt;/span&gt;&lt;span class="attrv"&gt;&amp;quot;All&amp;quot;&lt;/span&gt;&lt;span class="attr"&gt; timeout=&lt;/span&gt;&lt;span class="attrv"&gt;&amp;quot;10&amp;quot;&lt;/span&gt;&amp;gt;&lt;br /&gt;        &amp;lt;&lt;span class="tag"&gt;credentials&lt;/span&gt;&lt;span class="attr"&gt; passwordFormat=&lt;/span&gt;&lt;span class="attrv"&gt;&amp;quot;&lt;b&gt;SHA1&lt;/b&gt;&amp;quot;&lt;/span&gt;&amp;gt;&lt;br /&gt;          &amp;lt;&lt;span class="tag"&gt;user&lt;/span&gt;&lt;span class="attr"&gt; name=&lt;/span&gt;&lt;span class="attrv"&gt;&amp;quot;&lt;b&gt;minigweek&lt;/b&gt;&amp;quot;&lt;/span&gt;&lt;span class="attr"&gt; password=&lt;/span&gt;&lt;span class="attrv"&gt;&amp;quot;849B563ED0CFA086B0C33D2772E26E098903A3F3&amp;quot;&lt;/span&gt;/&amp;gt;&lt;br /&gt;          &amp;lt;&lt;span class="tag"&gt;user&lt;/span&gt;&lt;span class="attr"&gt; name=&lt;/span&gt;&lt;span class="attrv"&gt;&amp;quot;&lt;b&gt;kenshin&lt;/b&gt;&amp;quot;&lt;/span&gt;&lt;span class="attr"&gt; password=&lt;/span&gt;&lt;span class="attrv"&gt;&amp;quot;3A1CC647FFFCD2D717F03B4005A71395BD17731E&amp;quot;&lt;/span&gt; /&amp;gt;&lt;br /&gt;        &amp;lt;/&lt;span class="tag"&gt;credentials&lt;/span&gt;&amp;gt;&lt;br /&gt;      &amp;lt;/&lt;span class="tag"&gt;forms&lt;/span&gt;&amp;gt;&lt;br /&gt;    &amp;lt;/&lt;span class="tag"&gt;authentication&lt;/span&gt;&amp;gt;&lt;br /&gt;    &amp;lt;&lt;span class="tag"&gt;authorization&lt;/span&gt;&amp;gt;&lt;br /&gt;      &amp;lt;&lt;span class="tag"&gt;&lt;b&gt;deny&lt;/b&gt;&lt;/span&gt;&lt;span class="attr"&gt; users=&lt;/span&gt;&lt;span class="attrv"&gt;&amp;quot;?&amp;quot;&lt;/span&gt;/&amp;gt;&lt;br /&gt;      &amp;lt;&lt;span class="tag"&gt;&lt;b&gt;allow&lt;/b&gt;&lt;/span&gt;&lt;span class="attr"&gt; users=&lt;/span&gt;&lt;span class="attrv"&gt;&amp;quot;*&amp;quot;&lt;/span&gt;/&amp;gt;&lt;br /&gt;    &amp;lt;/&lt;span class="tag"&gt;authorization&lt;/span&gt;&amp;gt;&lt;/pre&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;Which should basically allow any logged in user to browse any page and deny access to anonymous user. &lt;br /&gt;&lt;br /&gt;Using C# here , so my &lt;b&gt;Default.aspx&lt;/b&gt; has a login control , code for which is placed in &lt;b&gt;Default.aspx.cs&lt;/b&gt; , as done by default by Visual Studio , and the login button raises an event &amp;quot;&lt;b&gt;Authenticate&lt;/b&gt;&amp;quot;which calls the function &amp;quot;&lt;b&gt;Login1_Authenticate1&amp;quot;&lt;/b&gt; which has the following code :-&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&lt;pre class="coloredcode"&gt;&lt;span class="kwd"&gt;protected void&lt;/span&gt; Login1_Authenticate1(&lt;span class="kwd"&gt;object&lt;/span&gt; sender, AuthenticateEventArgs e)&lt;br /&gt;    {&lt;br /&gt;        Page.Validate();&lt;br /&gt;        &lt;span class="kwd"&gt;if&lt;/span&gt; (!Page.IsValid) &lt;span class="kwd"&gt;return&lt;/span&gt;;&lt;br /&gt;        &lt;span class="kwd"&gt;if&lt;/span&gt; (FormsAuthentication.Authenticate(Login1.UserName,Login1.Password))&lt;br /&gt;        {&lt;br /&gt;            FormsAuthentication.RedirectFromLoginPage(Login1.UserName, &lt;span class="kwd"&gt;false&lt;/span&gt;);&lt;br /&gt;          &lt;br /&gt;        }&lt;br /&gt;        &lt;span class="kwd"&gt;else&lt;/span&gt;&lt;br /&gt;        {&lt;br /&gt;            &lt;span class="cmt"&gt;// User name and password are not correct&lt;/span&gt;&lt;br /&gt;            Login1.FailureText = &lt;span class="st"&gt;&amp;quot;Invalid username or password!&amp;quot;&lt;/span&gt;;&lt;br /&gt;        }&lt;br /&gt;    }&lt;/pre&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;This should take care of authenticating a valid user. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Then there&amp;#39;s the logout page .&lt;br /&gt;Which has 3 controls.&lt;br /&gt;1.Loginname.&lt;br /&gt;2.Loginstatus.&lt;br /&gt;3.Logoutbutton.&lt;br /&gt;&lt;br /&gt;The Loginname control allows me to see who is logged in.&lt;br /&gt;The LoginStatus Control shows me whether use is logged in , and shows a url with &amp;quot;Log out&amp;quot; link. If I click on that , its supposed to log me out.&lt;br /&gt;The Login Button when clicked does the following :&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&lt;pre class="coloredcode"&gt;&lt;span class="kwd"&gt;protected void&lt;/span&gt; Button1_Click(&lt;span class="kwd"&gt;object&lt;/span&gt; sender, EventArgs e)&lt;br /&gt;    {&lt;br /&gt;&lt;br /&gt;        FormsAuthentication.SignOut();&lt;br /&gt;        FormsAuthentication.RedirectToLoginPage();&lt;br /&gt;    }&lt;/pre&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;hah ! Either of the loginstatus or the loginbutton should do the job of logging out the user and redirecting me to login page. Which it does. nice. &lt;br /&gt;&lt;br /&gt;But here in lies a problem.&lt;br /&gt;&lt;br /&gt;My Site has now 4 pages. &lt;br /&gt;&lt;br /&gt;Login.aspx , Logout.aspx , Welcome.aspx and SeeItems.aspx.&lt;br /&gt;&lt;br /&gt;When I manually type in the url to any of the site for the first time , i am redirected to Login page , as it should and all is fine. Now if I log in , I am taken to the page from where I was redirected to login page. neat eh ?&lt;br /&gt;&lt;br /&gt;I once visit Welcome.aspx , SeeItems.aspx and then Logout.aspx , where I click either on Loginstatus control or the Logout button. I am redirected back to Login Page ! &lt;b&gt;Bravo&lt;/b&gt; ! Which is all good , but !!! If now I manually type in the url to Welcome or Seeitems page I am still able to see these [pages !! how come ??&amp;nbsp; &lt;img src="http://forums.asp.net/emoticons/emotion-39.gif" alt="Super Angry" /&gt;&lt;br /&gt;&lt;br /&gt;I noticed , if i hit refresh now , i am taken back to login page . applicable to both the pages. This is odd isn&amp;#39;t it ?? If I am logged out ( which is true because immediately after logging out I am unable to visit the logout page anymore !!) , why can I still see those welcome and seeitems pages ? Its bugging the hell out of me and any help would be appreciated in resolving this &lt;img src="http://forums.asp.net/emoticons/emotion-42.gif" alt="Confused" /&gt;&lt;br /&gt;&lt;br /&gt;Thanks much in advance</description></item></channel></rss>