<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><category>pcsoft.us.windev</category><copyright>Copyright 2026, PC SOFT</copyright><lastBuildDate>14 Dec 2014 15:30:00 Z</lastBuildDate><pubDate>14 Dec 2014 11:54:00 Z</pubDate><description>Situation&#13;
I am building a website with WD18. It works with delicat medical data.&#13;
&#13;
A therapist can login to a specific environment via a personal url.&#13;
&#13;
Everybody has the same URL with a long randomized parameter.&#13;
&#13;
According to that link the system knows that is is a therapist, an administrator or a patient.&#13;
&#13;
Of course there is also a password asked. And not everybody has access to all the data.&#13;
&#13;
Now the problem.&#13;
&#13;
I login as a therapist via a valid link, fill in the pasword and have acces to my pages. Excellent.&#13;
&#13;
When I copy the URL and I use it with another browser, I have also acces to those pages without fill in the pasword&#13;
&#13;
http://127.0.0.1/WD180AWP/WD180Awp.exe/CTX_1288-0-KKnQyWlcVc-23120663/PAGE_BehandelaarLogin/SYNC_14246078&#13;
&#13;
I think the webserver sees a session that is not expired.&#13;
&#13;
When I do this twice it does not work anymore,&#13;
&#13;
Now the question&#13;
&#13;
How can I secure the site in a way it is not possible to access it from another URL&#13;
&#13;
Thanks,&#13;
&#13;
Willy Hermans</description><ttl>30</ttl><generator>WEBDEV</generator><language>en_US</language><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login/read.awp</link><title>Security on webdev login</title><managingEditor>moderateur@pcsoft.fr (El moderador)</managingEditor><webMaster>webmaster@pcsoft.fr (El webmaster)</webMaster><item><author>guest</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login-49489/read.awp</comments><pubDate>14 Dec 2014 15:30:00 Z</pubDate><description>You say you have:&#13;
-therapist&#13;
-admin&#13;
and patient.&#13;
They have different rights. So on some pages a therapist can edit and see t…</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login-49489/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login-49489/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login/read.awp">Security on webdev login</source><title>Re: Security on webdev login</title></item><item><author>guest</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login-49488/read.awp</comments><pubDate>14 Dec 2014 13:15:00 Z</pubDate><description>OK&#13;
&#13;
Again a lot of stuff and a lot of fun ;{)&#13;
&#13;
I know what to do until the end of this year.&#13;
&#13;
Many thanks for the ideas.&#13;
…</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login-49488/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login-49488/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login/read.awp">Security on webdev login</source><title>Re: Security on webdev login</title></item><item><author>guest</author><category>pcsoft.us.windev</category><comments>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login-49487/read.awp</comments><pubDate>14 Dec 2014 12:50:00 Z</pubDate><description>Hello Willy,&#13;
&#13;
There are different ways of doing what you want. Here are a few:&#13;
- Check the IP address of the client each time…</description><guid isPermaLink="true">https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login-49487/read.awp</guid><link>https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login-49487/read.awp</link><source url="https://forum.pcsoft.fr/es-ES/pcsoft.us.windev/49483-security-webdev-login/read.awp">Security on webdev login</source><title>Re: Security on webdev login</title></item></channel></rss>
