After Logout a user is able to see cached pages that may include secure information

From: day_drummond (ddrummond@cmisinc.com)
Date: 11/04/02


From: ddrummond@cmisinc.com (day_drummond)
Date: 4 Nov 2002 08:40:57 -0800


I have a web site that has several levels of security. The problem I
am having is when a user is logged out the browser back button lets
another user see the cached pages from the previous user. This would
not be an issue except some of the information cached may be
restricted based on security level.

When a user clicks Log Out I execute

   FormsAuthentication.SignOut()
   Response.Redirect("Login.aspx?ForceLogout=1")

This works fine. I want to know is there some property that can be
checked on the Application or an HTTP collection that will tell me if
the user is authenticated. I don't want to try to authenticate a user,
I just want to know if they are authenticated at the current time. I
could use a check on such a property to disallow browsing away from
the login page. I have seen suggestions to clear the browser cache or
to close the current browser and reopen the login page in a new
browser but these seem unfriendly to the user.

I am looking forward to a suggestion on how to prevent a user from
browsing back to secure information after FormsAuthentication.SignOut
has been executed.

Thanks
Daylan Drummond
Software Engineer
Election.com



Relevant Pages

  • Re: Microsoft Browser Under Scrutiny
    ... I already know this, I subscribe to Microsoft Security Updates, and I have ... especially Outlook and Internet Explorer. ... > ubiquitous Internet Explorer browser. ...
    (microsoft.public.windowsxp.basics)
  • Re: Microsoft Browser Under Scrutiny
    ... I already know this, I subscribe to Microsoft Security Updates, and I have ... especially Outlook and Internet Explorer. ... > ubiquitous Internet Explorer browser. ...
    (microsoft.public.windowsxp.newusers)
  • Re: Microsoft Browser Under Scrutiny
    ... I already know this, I subscribe to Microsoft Security Updates, and I have ... especially Outlook and Internet Explorer. ... > ubiquitous Internet Explorer browser. ...
    (microsoft.public.windowsxp.general)
  • Re: [Full-Disclosure] RIP: ActiveX controls in Internet Explorer?
    ... > source of security holes in Internet Explorer. ... > judgment against Microsoft for patent infringement. ... > Internet Explorer rather than pay Eolas any more money. ... > Internet Explorer browser looks like the perfect time to put pressure on ...
    (Full-Disclosure)
  • Re: Critical error 101 on MS AntiSpyware install
    ... Not to mention everyone and their brother that is on the firefox high ... low and behold - Windows Help opens up - hum, ... because the one thing that was on on my little browser was the little ... Just use windows security, and not ignore ...
    (comp.security.misc)