Re: Back Buttons and Forms

From: Date: Sun, 27 Aug 2000 03:32:21 +0000
Subject: Re: Back Buttons and Forms
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-13824@lists.php.net to get a copy of this message
> I'm trying to use Header() functions to prevent browsers from caching a > username/password protected page (linked to a database), so that users can't > simply click the Back button to return to that page. The Headers work OK in > that the page isn't cached (the browser says it has 'expired'); so far so > good. But the browser offers the user the opportunity to reload the page by > reposting the form data that created it - which it does; so the whole > routine is useless. I've tried adding Header functions to all the > pages/scripts involved, to no avail. (I'm testing all this using whatever > version of Netscape that ships with Red Hat 6.2). Can't find anything really > relevant in the last couple of months on this list. > > Any ways around this? What's the problem with the way this is working? Do you want them to have to enter a username and password every time they see the page? If you want them only to see the page once per session, then you'll have to implement that on the server side. What's happening is that the user can't look at what the page was, but he can repost form data (and session data, if there is any -- for authentication) to see the page. Sounds like you need to keep authentication info in the user's session. By the way, pages that use PHP4 sessions are not cached by default. Dean.

« previous php.general (#13824) next »