Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6179617
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 24, 20262026-05-24T00:42:01+00:00 2026-05-24T00:42:01+00:00

Im using autologin on my MVC 3 website. How do I best handle this

  • 0

Im using autologin on my MVC 3 website.

How do I best handle this problem:

A user signs in at his own computer (and gets a 30 day cookie)

Same user signs in at a friends computer (and gets a 30 day cookie)

Its now possible to autologin in at both computers. The user realizes this and changes his password but his friend is still able to autologin from his computer until the cookie expires.

How do I best handle this?

I could of course set at date on the user when password changed and check this up against the date in the cookie.

Or am I missing something?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-24T00:42:02+00:00Added an answer on May 24, 2026 at 12:42 am

    I know what you’re saying, but I think you’re implying an association between the “remember me” function and the “password change” function which in practice, isn’t there. The auth token you get when authenticating is not generally tied to the value of the password (i.e. when using the membership provider), after all, you’re logically keeping the identity authenticated across sessions and in this regard, it works just fine.

    To be honest, this sounds like more of a user behaviour problem than a technology problem. In your use case, someone is consciously asking the browser to allow them to remain authenticated for a long period of time and doing so on a machine which they have no control over. Of course I’m assuming you have a “remember me” checkbox and if you don’t, there’s your answer right there.

    The other thing you might want to look at is what OWASP talks about in part 3 of the Top 10 – Broken authentication and session management. This link will put it in a .NET context for you but in short, it talks a lot about reducing the opportunity for exactly what you’re describing to happen by things like eager session expiration, disabling sliding sessions and obviously giving end users the control to expire the token at session expiration and log out at any time.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Using Authlogic, the time format for @user.last_login_at looks like this: Mon Apr 12 16:52:56
Im using HttpCLient to autoLogin a website. I an getting statusCode as '200'. API
I am using Authlogic for my user authentication, and would like yo add roles
I'm using Authlogic with my Ruby on Rails App. I would like user to
Im trying to test my successfully creates a new user after login (using authlogic).
I'm following the Railscasts tutorial on using OpenID with AuthLogic . This command: $
I'm building an autologin system using cookies, but one fundamental part of the functionality
How are you supposed to create an autologin feature on your webpage using phpass
We're using authlogic, and we want to have a user accounted created and the
I've been stuck on this very simple problem for hours now and Ive been

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.