Prevent Login Twice

All,
I'm tryinig to think of a way to prevent a person from logging into an application more than once at the same time. IE, the user logs into and application, then turns around to a different computer and attempts to login there. I wish to prevent that second login. At the moment, I can't think of a way to prevent that since each session gets a new session id.
Any thoughts are appreciated!

Hello,
In theory...easy.
In practice...incredibly difficult to do successfully (i.e. almost every way can be circumvented).
There are two solutions to this that I'd recommend if you really want to go down this route. Neither of them is APEX specific really -
1) Use client-side certificates. This will install an SSL certificate on the users computer, this will force a user into using a single machine to connect to your site. Obviously this has limitations (if their machine dies then they can't login from another machine). However it does work and lots of sites use this method (my online Bank used to use this method).
2) Use hardware. In other words issue your users with a hardware-key, such as the RSA key devices which they need to use to generate a one-time (time and key specific) code which they need to enter to login to the website. The advantage of this is that they can use the hardware device from different machines, it makes 'sharing' of the code much more difficult (the key cannot be physically shared easily, however it could be bypassed by reading out the code over the phone etc).
So, there are a couple of options if you really want to do this, however it's very much an effort/reward scenario, in other words you can spend a huge amount of effort trying to stop people from logging in more than once, but is that effort worthwhile in terms of what you're trying to protect (only you can decide that).
There are a few other methods I haven't mentioned (I'm sure other people will chime in), however it's definitely an area fraught with potential problems really.
John.
http://jes.blogs.shellprompt.net

Similar Messages

  • Login twice in same apex app by same user not possible

    Hi,
    In itself it is possible to login twice by same user in same appl.
    But when using both apps on diff pages eachtime the user is prompted to login again.
    Why is that and why cant'w we use the app twice by same user.
    It is possible to use same app by same user twice
    Thanks in advance,
    Hugo

    I think it is probably due to your cookie and the session state. I cannot use IE or FF to access the same application twice with the same id, otherwise if I do different searches or change pages, the sesiion in the other window gets confused and starts showing session state varibale from the other window. This is with two different windows (not tabs) of IE or FF running.
    But, I can easily use IE, FF, and Chrome to access the same application with the same credentials, and everything will work as if I logged in with three different ids. I barely remember this 'problem' from 'the old days', and cookies had something to do with it. It "may" have been that the solution (in some cases, depending on what you and the app are doing), was during the authenication process that every app creates and uses a cookie with the same name.
    Hope this helps some,
    Bill Ferguson

  • Why do I have to login twice after sleep mode?

    Until recently I have been able to login one time with a password to get to my desktop. Now I have to login twice and I have no idea why. I am running Yosemite, whatever the newest version is. I'm not too tech savvy, but have checked every setting I can think of to no avail. Any help would be appreciated.

    Just to be clear, it's not normal to have to log in twice when FV is on. If you want to try to solve that problem, ask for instructions.

  • How to prevent submit twice?

    i just use jsp and jstl.
    There is some way can prevent submit twice?
    i use sql in jdbc, first get the last record in table, compare the submit data and the last record, if same, prevent submit.
    but it can't check the date -- not the last record, same with the submit record.
    anyway can do it?

    what he/she is saying that you can put unique key on you databse that you cannot duplicate inserting records.. another way is to put javascript confirm box.. that way your client has to click ok to submit your form and it can prevent the user from double clicking your submit button.

  • Login twice to Query Designer

    Hi
    We are facing an issue, where we have to login twice, when we start either the Query Designer or the Web Application Designer. When I start up, choose a system and logon, I get a pop up message saying "The standard transport system is active. SAP GUI connection is not activated for current connectoin to BI system. Do you want to reconnect to BI system and activate SAP GUI connection?" When I click "Yes", I have to logon again.
    Is there a way to get around this popup?
    Cheers,
    Jacob Vennervald

    Hi Jacob,
    Go To RSA1---> Transport connection view
    In the menu Edit -
    >Transport----->Switch-off Standard.
    Now try opening Query Designer.
    Hope it helps!
    Best regards,
    Saurabh

  • Forced to login twice

    Recently I've been experiencing a weird issue with my macbook pro, and i'm not too sure what the first point of call should be to troubleshoot. Every time I log into my machine (macbook pro), it will without fail get me to log on twice. Basically it works as follows:
    1) Boot up machine and it takes me to login screen (there are 2 user accouts on the mac)
    2) Put in credentials - here it processes something for a while before my machine reboots
    3) Takes me back to login screen without any acknowledgement of what happened
    4) Login again and it takes me into my profile fine
    I'm currently on Lion 10.7.2

    UPDATE: I just heard back from PayPal, very quick response to my email actually (although when you first send it via the automated system, it emails you with a generic password issues email and you have to respond to that to get an actual human). But once I sent the second email, I got a very fast response. Here's my original email to PayPal: >>>My issue is that just in the last few weeks, I have to log in twice. The login on the PayPal home page won't accept my login like it used to, it always now sends me to a secondary login page where it says it needs more information from me. That login usually works, then takes me to the PayPal Verisign ID number entry page.     So I have to enter my username and password twice, which is bothersome because I use a long password.     It never used to do this before, I could always log in from the PayPal home page.  So something has changed in your system, or it's a bug?     There's a growing discussion about this problem in the PayPal Community, so I’m not the only one facing the problem:  https://www.paypal-community.com/t#/About-Business/I-m-being-forced-to-login-twice-every-time-from-every-device/td-p/######  >>> And here's the response from PayPal: >>>Thank you for contacting PayPal Customer Support. My name is ____ and I am happy to assist you with logging in.
    I do have a known issue about you having to log in multiple times. I have added your account to the ticket #141113-000212. In the mean time I would try and delete your cache and cookies or try a different internet browser to see if the same issue occurs. If it does still occur please know we are working to resolve the issue. Please let me know if you need further assistance.>>> I tried deleting the cache and cookies (Chrome) and trying another browser (Firefox) that I have set to never save cookies or cache but I still get the same multiple login request.  So here's hoping they get it fixed soon, the good news is they're working on it.

  • All secure websites ask for login twice

    I have banking, paypal, google, yahoo, Amazon, Netflix all say the first time I login that the user name or password is wrong and when I enter the same user name and same password the second time it logs on. Sounds like a key logger. Win 7 64, most current Firefox, fairly new win 7 install, new computer, New router Netgear 6300, Vipre Internet Security. This all just started on Wednesday.

    A client-side keylogger isn't going to make you type everything twice. But a DNS hijacker might. Have you already changed those passwords?
    Please check your connection setting here:
    "3-bar" menu button (or Tools menu) > Options > Advanced > Network mini-tab > "Settings" button
    The default of "Use system proxy settings" will piggyback on your Windows/IE "LAN" settings. You could try "No proxy" to see whether that makes any difference.
    Your system-level DNS servers can be discovered using a command prompt.
    Start menu > search box, type '''cmd.exe''' and press Enter
    At the prompt, type '''nslookup mozilla''.''org''' and press Enter
    Windows should report your current DNS server by name and address, as well the info for mozilla.org. For example:
    Server: cdns01.comcast.net
    Address: 75.75.75.75
    Non-authoritative answer:
    Name: mozilla.org
    Addresses: 2620:101:8008:5::2:1
    63.245.215.20
    If the server is not the one you normally associate with your internet service provider, or one you set up manually (e.g., for OpenDNS or Google Public DNS), then that would be suspicious. Note that DNS can be set in Windows and/or in your router.

  • OnBeforeLogin - Preventing Login

    Does anyone know of a way to use the login PEI to capture a login event and then prevent the login from occurring? Even if the user entered a correct username/password, I would like the method to stop the login from occuring, then return a generic error message to the user.
    Thanks in advance!

    A suggestion, it is NOT perfect...
    You will need to be using custom authentication... In this setup, you will add a column to the table with user names, call it online and use a char1. when your user logs in, and you are checking their authentication, if it passes, you update the table with a 'Y' in the row with their id.
    When they logout, you will run a process to update the same table, changing the 'Y' to 'N' or null..
    So when a user logs in, you will also check their user row an if the column is set to 'Y', then your custom authentication SHOULD return the error that that login is already logged in..
    Thank you,
    Tony Miller
    Webster, TX
    Follow your passion; the rest will take care of itself.
    JMS
    If this question is answered, please mark the thread as closed and assign points where earned..

  • Prevent Login Dialog Box Popup In EssVConnect

    Using VBA code to automate worksheets. Our site updates and switches servers about every 2 hours. Code works great when 'server' is up but when switched and we don't know which one is active, the EssVConnect pops up the Login Dialog box requiring us to switch server names and press OK. This means it is not automated. We want to prevent the box from appearing and get a bad return code instead so we can cycle through all the servers until we find one that is active. Documentation implies it will do this. We have tried setting all messages off (EssVSetGlobalOption(5, 4)) but that does not seem to work for the dialog box. Any suggestions?

    I am trying to remember if there are any issues and I think there is.. If I remember correctly, the EsbInit will not do what you want if called from within Excel VBA when the Essbase add-in is loaded because the C API used within the Excel add-in has already initialized the API with the wrong setting. You could try it..
    Further, the result of EsbAutoLogin is to get an context handle (hCtx). The problem is, then, that you can't use that context handle to do Excel add-in operations. The opposite situation, where you can get the hCtx from a worksheet connected to Essbase is not only possible but is the recommended way to combine the VB API with the Excel add-in. Look at the GetHctxFromSheet function to see how to use that capability.
    The only solution I can think to do what you want to do is to create an ActiveX EXE in VB 6 and have that ActiveX EXE call the EsbInit, etc and validate the server you need to login at a specific time. As it runs in a separate process and loads the Essbase API dlls at your command (EsbInit), you can control everything there. You can then use the CreateObject command in VBA to instance the object and call methods on it; your method will check the login for a specific server can could return the appropriate error message for you so you could validate which server is currently available and then call that server in your EssVConnect call.
    Tim Tow
    Oracle ACE
    Applied OLAP, Inc

  • J_security_check error 404 login twice.

    Hi, i encountered a problem with authentication based on form and containter. I have a login.xhtml (later mapped to login.jsf) page that contains:
    <form action="j_security_check" method="post">
                            <div style="clear: both">
                                User:
                                <input type="text" name="j_username" size="25" class="textfield" tabindex="1"></input>
                                <input type="reset" value="Reset" class="button" tabindex="4"></input>
                            </div>
                            <div style="clear: both">
                                Password:
                                <input type="password" size="25" name="j_password" class="textfield" tabindex="2"></input>
                                <input type="submit" value="Submit" class="button" tabindex="3"></input>
                            </div>
                        </form>The authorisation is based on LDAP. The problem is when i open this login page in two separate tabs in the same browser. I log in to restricted page in the first tab, everything is ok. But when i try to log in in the second tab while still being logged in the first tab, i get error 404 service not available. Any ideas how to deal with such situation?

    +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
    what do you get when you enter in an invalid username/password - your logonError.jsp? page
    How do you access this page - is your destination page available, and working?
    I take it you are trying to access /RnsttHome.jsp
    Check the spelling of your URL - maybe try accessing another file under securlty to see if that one works?
    +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
    -- It doesn't really matter whether I enter a correct username/password or an invalid one, cause I get the 404 Error. I am not re-directed to the logonError.jsp at all. I can only see that the browser is looking for J_security_check...at least that's what is written on the url when I get the 404 error.
    e.g.
    http://localhost/myapplication/j_security_check
    -- The destination page is RnsttHone.jsp and it is working fine.I don't think that this is the problem.
    -- I have tried accessing other files as well.That's not the problem.They all have the same problem with j_security_check...
    Arapakis Giannis

  • Various process crashes prevent login to main user account

    Here's a good one. I can't log in to my main user account; here's the recap:
    Computer was acting slow and pausing a lot over past couple of weeks; I put it down to internet slowness at first, but after awhile I began closing down less-critical processes like .mac synchronization, mySQL, etc. Can't recall running any new installs recently, or updates, except perhaps Firefox.
    Checked the logs, saw that my old pal mdimport was crashing repeatedly, like every 15 seconds or so. That will slow things down! So I turned off the Spotlight indexing for all categories, and eventually made the hard disk a private item. mdimport still crashing.
    Ran permissions repair; some problems fixed, nothing too alarming in the logs (I think). Verified the hard disk; no problems found.
    At some point the main account became unable to log me in. The login window accepts a password and disappears, but after a little while a blue screen appears, and the login window returns. I am able to log in using a secondary more-or-less virgin account on this machine, which seems to work fine.
    Console logs reveal the constantly crashing mdimport, triggered anytime I attempt to log in using the main account. Secondarily, the loginwindow process is crashing on login (main account only) and crashdump itself is consistently crashing just afterwards. Occasionally another process called lsregister will crash at the login attempt, sometimes other processes too. More worryingly, there are reported IO errors from the kernel.
    I've reset the pram, I've reset the nvram. I've booted from a 10.5 system disk and re-run disk utility for permissions and repair disk. I tried safe mode.
    I've attempted to rsync my main user account to another computer while booted to target disk mode; rsync (running on the remote machine to which I'm copying the files) copies the many gigabytes in my Documents folder, but chokes consistently at some files in my Library ("former iDisk.dmg", App Support/firefox/profiles/etc, also some Growl files) with "Input/output error (5)."
    Anyone have any good theories? Many thanks in advance.
    --David H

    Thanks for your reply; I checked out the links but nothing seems too directly related. I'm vaguely aware of what mdimport does, but I certainly have seen it crash a lot.
    At this point, I'm finally able to log back in to my main account, which (with some caveats/questions below) seems to be working.
    To get back to this point, I used the terminal utility Applejack to clear caches, check plists for corruption, and clear virtual memory. I also manually deleted a loginwindow plist and some Library/Caches/com.apple.LaunchServices/ files. Something in there seemed to help, and I'm finally back in to the main user account. There was definitely no getting into this account before I tried these steps.
    Applejack is found at http://applejack.sourceforge.net/.
    I still have some troubling log entries, and some blips in several files. While subsequently backing up my user account, rsync consistently tripped on several files in /Library/Application Support relating to Firefox and Growl, in /Library/iCal, and also a couple of image files (out of tens of thousands) in my Pictures folder. So I deleted these files; the only concern so far is the iCal file which was called "corestorage.ics." And now that I've started iCal, it looks like I still have data; but my console log shows about 70 lines of "Calendaring data empty." Ugh. Nothing like losing data but not knowing what was lost.
    Also troubling in the system log: I have several entries of "kernel[0]: disk0s3: I/O error" (though not in the latest reboot cycle). Hard to tell if these belong in the same category as the many cryptic and possibly alarming messages seen there, or if this is a real warning of a failing hard disk, or of other corrupt files the system is running into. Again, disk utility has repeatedly found no problems.
    (Also I have several hundred entries of "/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/Metada ta.framework/Versions/A/Support/mdimportserver: _TIFFVSetField: tiff data provider: Invalid tag "Copyright" (not supported by codec)", which I hope relate to mdimport seeing many jpg images that have copyright metadata. I'm hoping that problem will go away now that they're marked "private" as far as Spotlight is concerned.)
    At least I'm back in the account. I'm trying to decide whether to archive & install system 10.5; I'd prefer to reformat a misbehaving disk, but then you gotta have pretty serious confidence in your backups. Alternatively if the rumors are true I'm hanging on for one of the new laptops; I'd prefer that to replacing the hard drive again in this diabolical case. (Price you pay for sleek, I guess.)
    Time will tell.

  • How to restrict a user to login twice

    hei evryone!
    Here's my prob... I need to restrict a user to login more than once meaning, if a certain user account is currently login , that account cannot be used concurrently using another window or machine... If another user attempts to login, using that same account an error message will be displayed saying "this user account is already logged in".. i tried to do this in javascript but the code that i've got only works for IE and its kinda hard to capture the event for closing window.. plus using onunload is not advisable with my situation since my webpage can be redirected to other codes meaning the cause of unloading the page could either be closing the browser or redirecting the window to another page such as window.location="anothercode.jsp";... I was wondering if there's a way to do this in jsp...
    Any suggestions, ideas, or sample codes would be deeply appreciated. Thanks in advance!
    btw, i need to generate a code that is cross browser.. What i really need to accomplish is to be able to determine when the browser is closed either by clicking the X button on the window, alt f4 or my own close button and not when the page is unloaded.
    Here's a sample code : This only works in IE =(
    ---------- default.jsp-------------------------
    <html>
    <head>
    <script language="Javascript">
         onunload=function(e) {      
         winX = navigator.appName=="Microsoft Internet Explorer" ? window.event.clientX : e.screenX;
         winY =navigator.appName=="Microsoft Internet Explorer" ? window.event.clientY :e.screenY;
    if (winX<0 && winY<0)
              // redirect to logout.jsp n do some stuff
    </script>
    </head>
    <body>
    Logout
    List
    View Schedules
    </body>
    </html>
    the default screen would be the code above: "default.jsp" wherein there are many ways that the page
    can be unloaded such as :
    - clicking the logout link
    - click the View Schedules
    - click the x button the left side of the window
    - alt f4
    - if the window is minimized , right click then select close option
    Now, what i needed to do is to determined when the browser is closed so i reset the login flag of the account and can be used later on.

    hei everyone!
    im tryin to resolve this prob by adding a session id field on the users table. Everytime a user logs in i will update the session id field so that if anyone attempts to use the same account i will redirect the later into the login page with a warning msg. I'll do this by comparing the session id that u got from the dbase and the session id from request.getSessionId() of the browser. However, my prolem now is how to cleanup my database.. i need the cleanup coz i have a user tracking screen wherein i cud show who's account are login n who's not. I have created an applet and embed it in all of jsp files so that i cud catch the event for closing window whether by using the x button of the window or a power intrerruption. However, i need to find a way where i cud determine whether the event was really a close window or just a redirection from another page. I mean , you could leave the page either by viewing another screen or by actually closing the window.. For instance, my main page has main menu which are (1) View Users and (2) View Schedule .By default, im in the "View Users" screen . These two menus have their corresponding jsp n both jsp files have an embeded applet. So if the user click the "View Schedules " screen or if the user chooses to click the logout button or window's x button to exit the browser, then the applet will call the stop method. This what i meant by how will i determine if the user really exits on my application or not.. Coz if the user clicks from one screen to another then, user actually does not leave my application the user only exit on my application if the user logs out or close the window..
    Please help me out on this matter... Thanks in advance!

  • Why do we have to login twice?

    When I go to the OTN site, it automatically recognizes me and logs me on. :)
    Then, when I go to forums on the OTN site, it immediately forgets who I am and I have to login. :( I'm on a slow internet connection which makes unnecessary page loads particularly annoying.
    What's the point of having a single sign-on if I have to use it multiple times. :)

    It's not the forums remembering who you are, it's the OTN website itself - I've noticed the same behaviour, and I've always put it down to the forums being on a separate authentication thingy-wotsit to the rest of the OTN site. Annoying as anything, but I don't think it'll change any time soon *{:-(                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       

  • Temporarily prevent login items while using FileVault2

    Hi everyone,
    in the past you could hold down shift while logging in and this would temporarily disable your login items so no windows would pop up. This still works in 10.9, but only when I am on the regular login screen. I am using FileVault so I have to enter my user password before the boot process and this user will get logged in. How can I achieve the shift key behaviour with FV enabled?
    Thanks
    Björn

    Is it simply not possible?

  • Login twice

    Hi,
    I have built an site with JSP, I authenticate the user, I put the username in session object...
    The problem is if a new browser window is opened and new session is created it lets one
    user to login even if he is already logged in in other window.
    So how should I see if an user is logged in and not to let him do that again.
    With application object? Is there one in JSP?
    Regards,
    Adrian

    Have a llok at, http://forum.java.sun.com/thread.jsp?forum=33&thread=259131. You can use the logic that I explained in Reply 1.
    Sudha

Maybe you are looking for

  • Creating datetime in XML format from ABAP

    Hello All:      I have a ABAP program that creates an XML file and everything is fine. I just need one date field in XML to conform to W3CC standard (EX: 2006-12-01T10:53:05.2170000). I need datetime in the format "2006-12-01T10:53:05.2170000". How d

  • When I try to access my add-ons, firefox freezes and I have to shut it down

    I never used to have any problems but started getting script errors. I have repaired this but now I cannot access my add-ons. Every time I click on it in the Tools menu, Firefox completely freezes and I have to shut it down.

  • View documents using uiwebview from server.

    I am uploading Documents(.png/.doc/.pdf/.xls ETC) on server from website. i have iPad App from where i need to view them. from DB i will get path like D:/Doc/Upload/test.pdf for every document. these is path of server where document is uploaded. is i

  • Emailing converted pdf docs

    I recently scanned multiple documents and they were in a jpg format.  I purchased this program and converted them to pdf.  Now I want to get them out of the program and attach to an email.  I am confused about how do do that.  Can anyone help me? Tha

  • Why are NEF files desaturating when selected in CS3 Bridge?

    I recently started shooting in RAW but when I select the images in CS3 Bridge, they desaturate.  It seems to only affect NEF files and not jpegs.