<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.asp.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security</title><link>http://forums.asp.net/25.aspx</link><description>All about ASP.NET security (authentication, authorization, membership, roles, etc.) and the Login controls. &lt;a href="http://aspadvice.com/SignUp/list.aspx?l=24&amp;c=17" target="_blank"&gt;Email List&lt;/a&gt;</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Re: Problems to logout without a loginstatus in vs2008</title><link>http://forums.asp.net/thread/3275344.aspx</link><pubDate>Sun, 05 Jul 2009 12:18:26 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3275344</guid><dc:creator>ClaCS</dc:creator><author>ClaCS</author><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3275344.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=3275344</wfw:commentRss><description>&lt;p&gt;Thanks. I&amp;#39;ll try with that code&lt;/p&gt;</description></item><item><title>Re: Problems to logout without a loginstatus in vs2008</title><link>http://forums.asp.net/thread/3274400.aspx</link><pubDate>Sat, 04 Jul 2009 07:30:50 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3274400</guid><dc:creator>akhhttar</dc:creator><author>akhhttar</author><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3274400.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=3274400</wfw:commentRss><description>&lt;p&gt;Hi,&lt;/p&gt;&lt;p&gt;In master page you need to have following code to disable Back button fuctionality by disabling client side content caching,&lt;/p&gt;&lt;p&gt;Response.Buffer = True&lt;br /&gt;Response.Cache.SetCacheability(HttpCacheability.NoCache)&lt;br /&gt;Response.ExpiresAbsolute = DateTime.Now().AddDays(-1)&lt;br /&gt;Response.Expires = -1500&lt;br /&gt;Response.CacheControl = &amp;quot;no-cache&amp;quot;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Thanks&lt;/p&gt;&lt;p&gt;Muhammad Akhtar Shiekh&lt;br /&gt;&lt;/p&gt;</description></item><item><title>Problems to logout without a loginstatus in vs2008</title><link>http://forums.asp.net/thread/3273861.aspx</link><pubDate>Fri, 03 Jul 2009 17:11:50 GMT</pubDate><guid isPermaLink="false">4c671506-2930-414c-a40b-8bf57ded5924:3273861</guid><dc:creator>ClaCS</dc:creator><author>ClaCS</author><slash:comments>0</slash:comments><comments>http://forums.asp.net/thread/3273861.aspx</comments><wfw:commentRss>http://forums.asp.net/commentrss.aspx?SectionID=25&amp;PostID=3273861</wfw:commentRss><description>&lt;p&gt;hi! &lt;img src="http://forums.asp.net/tiny_mce/jscripts/tiny_mce/plugins/emotions/img/smiley-wink.gif" alt="Wink" title="Wink" border="0" /&gt;&lt;/p&gt;&lt;p&gt;I have a little project with forms authentication&lt;br /&gt;&lt;br /&gt;web.config&lt;br /&gt;--------------&lt;br /&gt;&amp;lt;authentication mode=&amp;quot;Forms&amp;quot;&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;forms defaultUrl=&amp;quot;~/Login.aspx&amp;quot; loginUrl=&amp;quot;~/Login.aspx&amp;quot; /&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/authentication&amp;gt;&lt;br /&gt;&lt;br /&gt;I have 2 roles (&amp;#39;admin&amp;#39; and &amp;#39;user&amp;#39;) and, for the moment, 3 pages&lt;br /&gt;&lt;br /&gt;Login.aspx (with a login control)&lt;br /&gt;admin/adminPage.aspx&lt;br /&gt;user/userPage.aspx&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;admin web.config&lt;br /&gt;----------------------&lt;br /&gt;&amp;nbsp;&amp;lt;authorization&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;allow roles=&amp;quot;admin&amp;quot; /&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;deny users=&amp;quot;*&amp;quot; /&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/authorization&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;user web.config&lt;br /&gt;---------------&lt;br /&gt;&amp;nbsp;&amp;lt;authorization&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;allow roles=&amp;quot;user&amp;quot; /&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;deny users=&amp;quot;*&amp;quot; /&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/authorization&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;the adminPage.aspx and userPage.aspx have a masterpage&lt;br /&gt;&lt;br /&gt;The login process is correct, the &amp;#39;admins&amp;#39; enter to admin&amp;#39;s pages and the &amp;#39;users&amp;#39; enter to user&amp;#39;s page&lt;br /&gt;&lt;br /&gt;The masterpage has a button (ID=btnLogout) and a loginName control I try logout dynamically with this button but I can&amp;#39;t&lt;br /&gt;&lt;br /&gt;I try with differents codes on the btnLogout_click&lt;br /&gt;&lt;br /&gt;FormsAuthentication.SignOut()&lt;br /&gt;Context.User = Nothing&lt;br /&gt;Session.Abandon()&lt;br /&gt;Session.Clear()&lt;br /&gt;&lt;br /&gt;and FormsAuthentication.RedirectToLoginPage&lt;br /&gt;&lt;br /&gt;When I press the button the browser shows me the Login page :) but When I press the back button (on the browser)&lt;br /&gt;it shows me the last visited page (admin/adminPage.aspx if the last user was an &amp;#39;admin&amp;#39; and user/userPage.aspx if the last user was an &amp;#39;user&amp;#39;)&lt;br /&gt;It seems the logout process didn&amp;#39;t close the session totally (or correctly)&lt;br /&gt;&lt;br /&gt;so... How Can I do logout dynamically?? ...I need do it without a LoginStatus &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;sorry for my english :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards&lt;/p&gt;</description></item></channel></rss>