Re: Back Buttons and Forms
| From: | Dean Hall | Date: | Sun, 27 Aug 2000 03:32:21 +0000 |
| Subject: | Re: Back Buttons and Forms | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-13824@lists.php.net to get a copy of this message | ||
> I'm trying to use Header() functions to prevent browsers from caching a
> username/password protected page (linked to a database), so that users
can't
> simply click the Back button to return to that page. The Headers work OK
in
> that the page isn't cached (the browser says it has 'expired'); so far so
> good. But the browser offers the user the opportunity to reload the page
by
> reposting the form data that created it - which it does; so the whole
> routine is useless. I've tried adding Header functions to all the
> pages/scripts involved, to no avail. (I'm testing all this using whatever
> version of Netscape that ships with Red Hat 6.2). Can't find anything
really
> relevant in the last couple of months on this list.
>
> Any ways around this?
What's the problem with the way this is working? Do you want them to have to
enter a username and password every time they see the page? If you want them
only to see the page once per session, then you'll have to implement that on
the server side.
What's happening is that the user can't look at what the page was, but he
can repost form data (and session data, if there is any -- for
authentication) to see the page. Sounds like you need to keep authentication
info in the user's session.
By the way, pages that use PHP4 sessions are not cached by default.
Dean.