Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

stopping users getting back to the payment page

Posted on 2012-08-16
2
Medium Priority
?
304 Views
Last Modified: 2012-09-03
I'm looking for the common way in which to stop users getting back to the payment page.

Say for argumeny sake a successful payment occurs and the user is re-directed to the success page.

I'd like to be able to stop the user being able to get back to that same order page using the back button and re-submitting. I'm not interested in disabling the back button though....

Is there a common way of doing this?
0
Comment
Question by:scm0sml
2 Comments
 
LVL 23

Expert Comment

by:Roopesh Reddy
ID: 38303498
Hi,

You may have to clear the history so that, if the user clicks on back button, it won't redirect to that page!

http://www.codeproject.com/Tips/135121/Browser-back-button-issue-after-logout

Hope it helps u...
0
 
LVL 26

Accepted Solution

by:
Alan Warren earned 2000 total points
ID: 38303554
Hi scm0sml,

A combination of response headers and checking session variables set by pages that are permitted to refer the payments page should do it.

I doubt these things are ever really bullet-proof, but this example works pretty good.

Page_Init on your payments page:
    Protected Sub Page_Init(sender As Object, e As System.EventArgs) Handles Me.Init
        ' by setting these values, code on this page will trigger even if user uses the back button
        Response.AppendHeader("Cache-Control", "no-cache, no-store, must-revalidate") '  // HTTP 1.1.
        Response.AppendHeader("Pragma", "no-cache") '  // HTTP 1.0.
        Response.AppendHeader("Expires", "0")  ' // Proxies.
    End Sub

Open in new window


Page_Load on your Payments page:
    Protected Sub Page_Load(sender As Object, e As System.EventArgs) Handles Me.Load

        ' Only pages that set the session value to zero can refer this page
        If Session("Making_Payment") > 0 Then
            Response.Redirect("~", True)
        End If

    End Sub

Open in new window


Page_Init on your pages that are allowed to refer the payments page:
    Protected Sub Page_Init(sender As Object, e As System.EventArgs) Handles Me.Init
        ' always set the session value to zero on pages that can refer the payments page
        ' because the payments page will redirect if the session value is not equal to zero
        If Session("Making_Payment") Is Nothing Then
            Session("Making_Payment") = 0
        Else
            Session("Making_Payment") = 0
        End If

    End Sub

Open in new window


Page_Init on your Success page:
    Protected Sub Page_Init(sender As Object, e As System.EventArgs) Handles Me.Init
        Session("Making_Payment") = 1
    End Sub

Open in new window


hth
Alan ";0)
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

User art_snob (http://www.experts-exchange.com/M_6114203.html) encountered strange behavior of Android Web browser on his Mobile Web site. It took a while to find the true cause. It happens so, that the Android Web browser (at least up to OS ver. 2.…
Real-time is more about the business, not the technology. In day-to-day life, to make real-time decisions like buying or investing, business needs the latest information(e.g. Gold Rate/Stock Rate). Unlike traditional days, you need not wait for a fe…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an anti-spam), the admin…
Despite its rising prevalence in the business world, "the cloud" is still misunderstood. Some companies still believe common misconceptions about lack of security in cloud solutions and many misuses of cloud storage options still occur every day. …
Suggested Courses

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question