[1729] in WWW Security List Archive
Re: User Auth.
daemon@ATHENA.MIT.EDU (Seth I. Rich)
Tue Mar 26 19:04:07 1996
Date: Tue, 26 Mar 1996 15:31:06 -0500
To: "S.W. Cheung" <swcheung@hkimd.cig.mot.com>, www-security@ns2.rutgers.edu
From: "Seth I. Rich" <seth@hygnet.com>
Errors-To: owner-www-security@ns2.rutgers.edu
>I got a question about User Auth. How can I force or allow my users to
>"logout" without quitting the client?
In my experience, if you send them a failed authentication response,
the browser will forget about the password it had been using,
effectively logging the user out. If the user wants in again, s/he
will have to re-authenticate.
Seth
---------------------------------------------------------------------------
Seth I. Rich - seth@hygnet.com - (610) 859-0100
Systems Administrator / Webmaster, HYGNet My words are my own; please
Rabbits on walls, no problem. don't blame my employer!