Pages can change their navigation or welcome message according to whether an authenticated user ID exists in Session. This is a presentation check; protected pages must still enforce authorization independently.
Welcome smo<input type="text" name="userid">
<input type="password" name="password"><% If IsEmpty(Session("userid")) Then %>
<a href="lg-login.php">Log in</a>
<% Else %>
Welcome <%= Server.HTMLEncode(Session("userid")) %>
<a href="logout.asp">Log out</a>
<% End If %>HTML-encode the Session value before displaying it. The login processing page should be responsible for validating credentials and creating Session("userid"); this page only reads that established state.
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.