How to not load previous page of website when clicking back button on browser with java using sessions?

Viewed 41

I have 4 jsp files, login.jsp index.jsp view.jsp logout.jsp.

When I login I create a session and pass in the username and password of the user.

I let him browse through index and view and I have a simple button in my navbar for the logout.

logout.jsp:

<%@ page language="java" contentType="text/html; charset=US-ASCII"
    pageEncoding="US-ASCII"%>
<!DOCTYPE html>
<html>
<head>
<meta charset="US-ASCII">
<title>Logout Page</title>
</head>
<body>

<h1>You have logged out of the system!</h1>

<a href="login.jsp">Back to the Login Page</a>

<%
    session.invalidate(); // destroy session

    response.setHeader("Cache-Control", "no-cache, no-store, must-revalidate"); // HTTP 1.1.
    response.setHeader("Pragma", "no-cache"); // HTTP 1.0.
    response.setHeader("Expires", "0"); // Proxies.
%>
</body>
</html>

In all of my .jsp files I have the following lines at the beginning:

response.setHeader("Cache-Control", "no-cache, no-store, must-revalidate"); // HTTP 1.1.
response.setHeader("Pragma", "no-cache"); // HTTP 1.0.
response.setHeader("Expires", "0"); // Proxies.

But if the user is in the logout.jsp webpage he can simply press the back button of the browser and go back to the previous page (either index.jsp or view.jsp).

However it correctly destroys the session but I don't want him to be able to go back.

1 Answers

There's a lot to cover in this question, so I'll try to be brief.

First, you have to keep in mind the following:

  1. HTTP is a stateless protocol
  2. Java code executes on the server when you submit an HTTP Request
  3. The OUTPUT from your Java process is sent to your browser as HTML, or JSON, or some other text in the HTTP Response (which also contains the HTTP response headers).
  4. If you are modifying the HTTP response within a Java JSP, it will execute on the server, and you will see the results in the response. (that's why the session is invalidated and you will see the headers disappear)
  5. Unfortunately, your browser doesn't care about what the Java code is doing and when you click the back button, you will submit a new HTTP Request to the previous JSP resource that you requested.

You could inspect the HTTP REQUEST to make sure you are not adding headers that would reinstate the session and/or authenticate your user.

Another classic solution to this sort of problem would be to use a what's called the MVC (Model-View-Controller) design pattern, and perform authentication and session management within the Controller component(s). In this approach, your JSP files constitute part of the VIEW component, and you can easily delegate from specific controller methods to specific views. There are many many resources for doing this in Java. Here's a simple tutorial using JSP and Servlets:

Regardless of the coding approach you take, every component that handles an inbound HTTP request must inspect it to make sure the current user is authenticated. If not, then display the login page. This is easier within a control component, but you can do it in JSP as well, though you might need to import another JSP to do the authentication check in order to not have to copy the same code into multiple files.

Related