The "right" or "normal" ways to check if a user is logined already and show different pages...

Posted on 2006-05-14
Last Modified: 2010-04-01
Hi, currently in my jsp, i use the below "ways" to check if the user is loginned, if he is, then it will show the jsp page, else, it will be FORWARDed to login.jsp:

<!-- Check for login status -->
    <jsp:useBean id="loginstatus" class="data.LoginStatus" scope="session"/>
    if(session.getAttribute("id") == null || session.getAttribute("id").equals("")){
        loginstatus.setStatusMsg("You must login first dude.");
        <jsp:forward page="login.jsp"/>

but after reading some reference books, they all said that DO NOT use forward, but use RequestDispatcher.forward instead. Then I come out with an idea of checking if the user is loginned in my servlet, if yes, then use requestdispatcher's forward to the targetted jsp, else, to login page....
but after another careful thought, i realize that the user can directly enter the link to my jsp page (by passing the servlet, eg: http://host/level1/level2/view_critical_data.jsp).. means they still can view the page even if they aren;t logined!

so, please.. anyone or every experts here, kindly show me the real/professional/correct ways in achieving my "goal"...
Question by:InNoCenT_Ch1ld
    LVL 11

    Accepted Solution

    Hi, In your case the servlet filter will best suit the need. For more information see here

    Using servlet filter and keeping the mapping for all pages, one ensure that any request will definitely go thru servlet filter and there u can have the check for "id" or any other session identifier and then better forward to login page or destination page.
    LVL 3

    Author Comment

    tks for the respond, fargo ;-)
    but it seems kind of "complicated" to use for a new user like me...

    do u use it before? any chance i can get a crash course from you or anyone/ any website?
    LVL 11

    Expert Comment

    Following two links may help you.

    I do use servlet filter for many purposes. I have no time at the moment as i m busy with my projects. Please try to follow the above two links and let us know if u face any problems.
    LVL 3

    Author Comment

    tks.. i think it should be sufficient.

    Featured Post

    6 Surprising Benefits of Threat Intelligence

    All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

    Join & Write a Comment

    Outlook Free & Paid Tools
    If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
    Internet Business Fax to Email Made Easy - With eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
    In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor ( If you're interested in additional methods for monitoring bandwidt…

    730 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now