【问题标题】:Checking if Session has Timed Out检查会话是否超时
【发布时间】:2011-03-26 09:51:21
【问题描述】:

这是我所有页面的基类,除了 EndSession.aspx

override protected void OnInit(EventArgs e)  {  
base.OnInit(e);  

if (Context.Session != null)  
     {  
         //check the IsNewSession value, this will tell us if the session has been reset.  
         //IsNewSession will also let us know if the users session has timed out  
         if (Session.IsNewSession)  
         {  
            //now we know it's a new session, so we check to see if a cookie is present  
             string cookie = Request.Headers["Cookie"];  
             //now we determine if there is a cookie does it contains what we're looking for 
             if ((null != cookie) && (cookie.IndexOf("ASP.NET_SessionId") >= 0) )//&& !Request.QueryString["timeout"].ToString().Equals("yes"))  
             {  
                 //since it's a new session but a ASP.Net cookie exist we know  
                 //the session has expired so we need to redirect them  

                 Response.Redirect("EndSession.aspx?timeout=yes");  
             }  
         }  
     }  
 } 

但在 EndSession 上,我尝试返回到 default.aspx,然后上面的代码只是重定向回 EndSession.aspx。

所以为了更好地说明: 第 1 步:转到 mypage.aspx 步骤 2:等待超时 第 3 步:尝试离开 第 4 步:重定向到 EndSession.aspx 第 5 步:尝试离开 第 6 步:转到设置 4

Setp 6 实际上应该能够离开...

(如果需要请进一步澄清)

有什么想法吗?

谢谢!!!

【问题讨论】:

  • 您实际上想实现哪些您无法实现的目标,比如说 FormsAuthentication?我的意思是你重定向到 default.aspx 的原因是什么,那里应该发生什么魔法?
  • 我对其他想法持开放态度。尽管我应该提到我并不担心尝试对用户进行身份验证。会话状态中存储了其他内容,如果意外删除它们可能会导致问题。我对更好的选择持开放态度,但我仍然认为我想做的事情应该是可以实现的……不是吗?

标签: asp.net session timeout


【解决方案1】:

我摆脱了我最初拥有的基本页面。

把这个放在 Global.asax 的 Session_Start 中

void Session_Start(object sender, EventArgs e) 
{
    string cookie = Request.Headers["Cookie"];
    // Code that runs when a new session is started
    if ((null != cookie) && (cookie.IndexOf("ASP.NET_SessionId") >= 0))//&& !Request.QueryString["timeout"].ToString().Equals("yes"))  
    {
        if(Request.QueryString["timeout"] == null || !Request.QueryString["timeout"].ToString().Equals("yes"))
            Response.Redirect("Default.aspx?timeout=yes");
    }
}

把这个放在 Defualt.aspx 页面上:

 if (!IsPostBack)
    {
        if (Request.QueryString["timeout"] != null && Request.QueryString["timeout"].ToString().Equals("yes"))
        {
            Response.Write("<script>" +
               "alert('Your Session has Timedout due to Inactivity');" +
               "location.href='Default.aspx';" +
               "</script>");
        }
    }

即使 Default.aspx 页面发生超时,此解决方案也有效

我使用的解决方案的讨论发布在这里:How to stop basepage from recursivly detecting session timeout

【讨论】:

    猜你喜欢
    • 2011-09-04
    • 2011-09-01
    • 1970-01-01
    • 2013-01-19
    • 2014-03-11
    • 2011-11-02
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多