ASP.NET
  Home arrow ASP.NET arrow Page 4 - Preventing Simultaneous Logons
ASP Free Forums 
.NET  
ASP  
ASP Code  
ASP.NET  
ASP.NET Code  
BrainDump  
C#  
Code Examples  
Database  
Database Code  
IIS  
Microsoft Access  
MS SQL Server  
Silverlight  
Visual Basic.NET  
Windows Scripting  
Windows Security  
XML  
Mobile Linux 
App Generation ROI 
IBM® developerWorks 
ASP Web Hosting  
ASP.NET Web Hosting 
Windows Web Hosting
 
Weekly Newsletter
 
Developer Updates  
Free Website Content 
 RSS  Articles
 RSS  Forums
 RSS  All Feeds
Write For Us Get Paid 
Request Media Kit
Contact Us 
Site Map 
Privacy Policy 
Support 
 USERNAME
 
 PASSWORD
 
 
  >>> SIGN UP!  
  Lost Password? 
ASP.NET

Preventing Simultaneous Logons
By: Vadivel Mohanakrishnan
  • Search For More Articles!
  • Disclaimer
  • Author Terms
  • Rating: 4 stars4 stars4 stars4 stars4 stars / 23
    2004-04-07

    Table of Contents:
  • Preventing Simultaneous Logons
  • The Traditional Approach
  • Data Caching to Our Rescue
  • The Solution

  • Rate this Article: Poor Best 
      ADD THIS ARTICLE TO:
      Del.ici.ous Digg
      Blink Simpy
      Google Spurl
      Y! MyWeb Furl
    Email Me Similar Content When Posted
    Add Developer Shed Article Feed To Your Site
    Email Article To Friend
    Print Version Of Article
    PDF Version Of Article
     
     
    ADVERTISEMENT


    Preventing Simultaneous Logons - The Solution


    (Page 4 of 4 )

    Getting back on the track of our course, we would be using the cache object with Sliding expiration and Application_PreRequestHandlerExecute of Global.asax to tackle this multiple login issue. As we have seen enough of the theory part, I think its time to look at some source code. For the purpose of testing, let us set the session timeout as 1.

    Sample: Global.asax.cs


    protected void Application_PreRequestHandlerExecute(Object senderEventArgs e)
    {
     
    if(Session["UserDetails"]!=null
     
    {  
        string strCacheKey 
    Session["UserDetails"].ToString();
        string strUser 
    HttpContext.Current.Cache[strCacheKey].ToString();
     

    }

    Sample: Login Page


    Private void BtnLogin_Click(object senderSystem.EventArgs e)

    string strConCat 
    TxtUserName.Text+TxtPassword.Text;
    string strUser 
    Convert.ToString(Cache[strConCat]);
       
     
    if (strUser==null || strUser.Equals(String.Empty))
     
    {
        TimeSpan SessTimeOut
    =new TimeSpan(0,0,Session.Timeout,0,0);
        Cache
    .Insert(strConCat,strConCat,null,DateTime.MaxValue,SessTimeOut,
     CacheItemPriority
    .NotRemovable,null);
        
    Session["UserDetails"] = strConCat;
        Response
    .Write("Welcome!");    
     
    }
     else
     
    {
        Response
    .Write("Duplicate login not allowed !!");
        
    return;
     
    }
    }

    That’s it! Easy, isn’t it? (Don’t forget to include System.Web.Caching in the login page). The username is almost always unique so we could even avoid concatenating the username and password.

    We can now compile the application and run it. After logging in, if you try to use the same username/password combination the application won’t authenticate you. The only way out is to wait until the Cache expires (I hope you now understand the reason for setting the session time out as 1). This holds good even if we try to login from two different browsers/machines.

    Conclusion

    The system requirement for testing this sample code is Windows 2000, XP or 2003 OS with IIS 5 (or 6) installed and .NET Framework 1.0. I have omitted the other necessary evils such as text editors! Happy programming!


    DISCLAIMER: The content provided in this article is not warranted or guaranteed by Developer Shed, Inc. The content provided is intended for entertainment and/or educational purposes in order to introduce to the reader key ideas, concepts, and/or product reviews. As such it is incumbent upon the reader to employ real-world tactics for security and implementation of best practices. We are not liable for any negative consequences that may result from implementing any information covered in our articles or tutorials. If this is a hardware review, it is not recommended to open and/or modify your hardware.

       · protected void Application_PreRequestHandlerExecute(object sender, EventArgs e) ...
     

    ASP.NET ARTICLES

    - More Advanced ASP.NET 3.5 Functions and Subr...
    - ASP.NET 3.5 Functions and Subroutines
    - Coding an IQ Test with Conditionally Driven ...
    - Developing Conditionally Driven Event Handle...
    - ASP.NET 3.5 Debugging Using Visual Web Devel...
    - Understanding Event Handlers in ASP.NET 3.5
    - Building a Web Form in ASP.NET and PHP: a Co...
    - Inserting Data into a Microsoft SQL 2008 Dat...
    - Creating an ASP.NET Dynamic Web Page Using M...
    - Retrieving Data from Microsoft SQL Server 20...
    - Building ASP.NET Web Forms to Use a MySQL Da...
    - Creating an ASP.NET Database using MS SQL 20...
    - Building an ASP.NET Website Using Include Ta...
    - Create ASP.NET Web Forms to Use a Microsoft ...
    - Editing Web Design Layout in Visual Web Deve...





    © 2003-2010 by Developer Shed. All rights reserved. DS Cluster 6 Hosted by Hostway
    For more Enterprise Application Development news, visit eWeek