man, it's really a very good idea. thanks alot.
but what if javascript was disabled! i will use your solution, but i'm still looking for some unbreakable solution. i really appreciate it
....:::::.... xxLargeWASP ....:::::....
It will kill the session when the browser is closed but only when the browser is closed (not if the user moves to another site).Using this and a combination of the above suggestions should help. Also provide users with a link to logout (basically a page which simply clears the session) .
Apart from the above there is no real way to determine if the user has gone away without using perhaps javascript and hidden frames and as we all know this can be switched off.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.