Author |
|
Guests Guest Group
Joined: 10 November 2003
Online Status: Online Posts: 262
|
Posted: 22 March 2005 at 6:26pm | IP Logged
|
|
|
I noticed that if you select the "Logout" link it takes you back to the login page, but if you press the back button in your browser it will take you to the previous page and you are logged in again without having to fill out the login form.
To get around this, I added code to clear out the id_user session variable on the login form. Thought you might be interested as this could be considered a security flaw.
|
Back to Top |
|
|
Alex AfterLogic Support
Joined: 19 November 2003
Online Status: Offline Posts: 2206
|
Posted: 23 March 2005 at 8:13am | IP Logged
|
|
|
Many thanks for the point! Now the problem is fixed.
Regards,
Alex
|
Back to Top |
|
|