Solved

HTTP_Referer HELP

Posted on 2003-11-24
2
842 Views
Last Modified: 2012-03-15
Hi All,
I have an Asp page test.asp for which one parameter needs to be passed for eg id=2  so to access the page in correct way the URL would be xyz.com/test.asp?id=2     Now the ID can be 2,3,4 etc ect It is generated dynamically.I dont want users to modify the ID in the address bar hence  I am checking whether request.serverVariable("HTTP_REFERER")<>""   and if it is <>"" then I am processing the page.

I am mailing the link xyz.com/test.asp?id=2 to the customer so if the users have hotmail account,yahoo account or for that matter any web based email account and the customer clicks on the above link the value returned by request.serverVariable("HTTP_REFERER") is not null (unless the customer modifies the ID in the address bar intentionally) .But if the customer has an exchange account for eg if my email lands in outlook express ot microsoft outlook  then the value returned by request.serverVariable("HTTP_REFERER") is null even thought the customer dint play with the the id in the Address bar . I dont want that to hapen .
Is there any solution to this problem Or is there any other alternative way?

Thanks for help
Ken
0
Comment
Question by:fdbtydh
2 Comments
 
LVL 1

Accepted Solution

by:
d0zerz earned 125 total points
ID: 9813128
I don't see how you're going to fix the referer problem from outlook, but I would prevent users from modifying the id with a session variable storing the id...something like this:

if strcomp(Request.QueryString("id"),session("id")) <> 0 _
 and not isNull(session("id")) then
  'error (user has modified ID)
elseif isNull(session("id")) then
  'User hasn't been assigned a sessionID yet
  '...assign an inital one
end if

I'm not sure exactly what kind of permissions you need with id, but you're going to have to come up with something to assign the session("id") initially when they come back from the email client...Probably in a similar way that you're assigning URL ids.  This could enforce that a user can only access a certain page if they have a session("id") AND it matches with the URL id.

I could probably come up with something better if I had some idea of the page "flow" and what you're trying to prevent them from doing :)
0
 

Author Comment

by:fdbtydh
ID: 9983323
I have used session variables and it worked .

Keny
http://www.houstonoptical.com  
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Suggested Solutions

I recently decide that I needed a way to make my pages scream on the net.   While searching around how I can accomplish this I stumbled across a great article that stated "minimize the server requests." I got to thinking, hey, I use more than one…
I would like to start this tip/trick by saying Thank You, to all who said that this could not be done, as it forced me to make sure that it could be accomplished. :) To start, I want to make sure everyone understands the importance of utilizing p…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now