Closing Browser upon Logging out
485927Jan 26 2006 — edited Mar 21 2006Hi all,
As the so many others who posted ( and still do) voicing their concern regarding the security whole that allows users to simply click the back button to see previously displayed data. I understand they won't be able to do anything without getting prompted by the login screen again, but the fact they can see it is scarey enough. I hope this thread puts this issue to rest at least if I can summarize it, suggest the different options available, and lead prospective inquirers in the right direction. Having read all related threads in this forum, I was disappointed to see replies either circumvente, ignore, or invalidate the issue altogether. The button line is there is no proposed solution (step by step) on how to prevent this other than generic suggestions that are probably none applicable any way.
I would like to challenge the experts in this forum to respond in a conclusive manner explaining a solution on a step by step basis (e.g. Oracle by example) approach. Form what I've seen, I can either unset the session cookie and close the browser window. Or, I can use some metadata tags somewhere in the page template to expire browser cache. I prefer to do this without closing windows, but I will be content if I'm shown how to do it.
I know expiring browser cache is doeable because our PeopleSoft application and my bank does it without closing my browser.
Again, for the htmldb experts among us, step in and show us your muscles!!!