Session is not expiring? RRS feed

  • Question

  • User57010809 posted

    Probably my question is stupid but it is driving me crazy, you see I have this application its session is not expiring after logging out even though I have used Session.Abandon(), Session.Clear(), and Session.Removeall(). I have been searching all over the internet but no luck so far and I really wish I can get some help. Say I have user X if I do the following any one can login with X's account:

    1. Login with X's username and password.
    2. Take Session ".ASPXFORMSAUTH" info.
    3. Logout from X's account
    4. Add the Session ".ASPXFORMSAUTH" with its value.
    5. type the URL and click enter

    the page just opens up and it is really driving me CRAZY!!

    Thanks in advance

    Tuesday, August 30, 2011 2:32 PM


  • User57010809 posted

    Thanks a lot Mamba, very useful links, but I went with SQLstate mode, I just tested it and it works fine.

    • Marked as answer by Anonymous Thursday, October 7, 2021 12:00 AM
    Saturday, September 3, 2011 6:25 AM

All replies