Restrict member-area access in Classic ASP

A member area should check authentication before protected content is rendered. A small include file makes the same Session check reusable across many ASP pages.

Include the access check

<!-- #include file="check.asp" -->

Put the include before protected page output.

Example check.asp

<%
If IsEmpty(Session("userid")) Then
  Response.Redirect "../lg-login.php"
End If
%>

The Session variable is only one part of authorization. For applications with roles or permissions, check those permissions on every protected operation rather than assuming that being logged in grants access to everything.

Use HTTPS so the authentication cookie is not exposed in transit, and provide an explicit logout action that abandons the Session.


ASP Home






✖
We use cookies to improve your browsing experience. . Learn more
HTML MySQL PHP JavaScript ASP Photoshop Articles Contact us
© 2000-2026 plus2net.com All rights reserved worldwide Privacy Policy Disclaimer