S
Srinivasa Raghavan Sethuraman
Hi,
I have a web site which uses formAuthentication. After the
logging in, i store the user credentials in a Session Variable which is
not updated any where in the website. After certain point it seems that
Users are able to view other people pages with their credentials, even
though on every web page initialize , a user context is set based on the
logged in session variable.
If there any chance of session variable of one user getting
updated/overlapping with users.
Thanks
Srinivasa Raghavan
*** Sent via Devdex http://www.devdex.com ***
Don't just participate in USENET...get rewarded for it!
I have a web site which uses formAuthentication. After the
logging in, i store the user credentials in a Session Variable which is
not updated any where in the website. After certain point it seems that
Users are able to view other people pages with their credentials, even
though on every web page initialize , a user context is set based on the
logged in session variable.
If there any chance of session variable of one user getting
updated/overlapping with users.
Thanks
Srinivasa Raghavan
*** Sent via Devdex http://www.devdex.com ***
Don't just participate in USENET...get rewarded for it!