Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 9173381
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 17, 20262026-06-17T16:34:35+00:00 2026-06-17T16:34:35+00:00

Objective Restrict direct URL access to all pages but Logon.aspx ensuring that a user

  • 0

Objective

Restrict direct URL access to all pages but Logon.aspx ensuring that a user must be referred to every other page.

Driver

The driver behind this requirement is our internal security department. They feel that this is the only acceptable solution to ensure the application is always secure.

Problem

The problem is two-fold, so let’s deal with the first one. If a user is logged in and on a page they can copy the URL, open up a new tab, close the previous tab, paste the URL, and the session is still alive. I understand why this is happening but they are saying we need to keep that from happening. And please don’t ask me why, if I could answer that I probably would be convincing them otherwise.

The second part of the problem is that the way the application was originally written (insert really angry face here) two of the web forms are reused for enrollment. This specifically means that those pages are accessible even if the user isn’t logged in. However, we have to make it so that they were specifically referred to those pages through the process flow and thus not directly accessible.

As an example for the aforementioned paragraph, consider the following. The user copies the URL to one of the shared forms, opens up a new browser, and pastes in the URL. The session is dead but the form displays for the purposes of enrollment. However, this is problematic because they haven’t accepted the terms and they have broken the already fragile flow.

What have I tried?

Honestly, nothing. I’m up here panning for ideas because the best I’ve seen thus far Googling is stuff surrounding ensure the user is logged in first. Some use cookies and others use the membership provider, but the fact that the user is logged in already doesn’t address either of my problems.

I look forward to hearing from you all!

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-17T16:34:37+00:00Added an answer on June 17, 2026 at 4:34 pm

    Once user has been logged into the system , what the point of hiding anything which you have given access. but anyways here might be few ways to do this:-

    For the first the My suggestion is to wrap your page inside an IFrame and disable the right click, so that you cannot access the view source or link information.

    Once above is achievable . you can also attach a token to every URL. then you can check the if token is available or not. If available , request is valid, else invalid request.

    I will give you more solution if crossed my mind.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Using Objective-C, how can I give/take the permissions for all user to read a
I have a series of interlinked web pages, and I want to restrict access
Objective: Convert an overgrown Excel sheet into an Access database, but maintain a front-end
Objective was: To change pages like details.aspx?GUID=903901823908129038 to clean ones like /adrian_seo Achieved: Now
Objective: I want to create a web service that allows me to connect to
Objective: In support of a Windows Service that may have multiple instances on a
The objective is to write a convenience method that return a ResultSet from a
Objective: Be able to nest a resource, like records inside of users so that
Objective Have a small magnifying glass icon that appears in the top right corner
Objective: Serialize all the public properties of the ClassMain: public class ClassMain { ClassA

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.