I'm new to JSP & Servlets and i'm facing the below issue.
In our product, there is a requirement like if HTTP 404 error is occuring, we've to direct the user to an error page. The error page should contain an error message and an link to the homepage. If the user is already logged in and if the session is valid, direct to home page or else to the login page.
I've implemented this by creating an error.jsp page and putting it in <error-page> tag of the web.xml.
Now please consider the below scenario.
1. I log into the application and wait till the session to time out. 2. Once the session is timed out, i click on a link to download an excel document. 3. Since the session has timed out, it directs me to the login page. 4. I give the proper user credentials and hit login button. 5. Pop-up window comes asking to save or open the document. 6. I hit cancel on the pop-up window. [The url is still pointing towards the excel document] 7. I'm still in the login page and i hit login button again with proper credentials. 8. It directs me to error page and from there to the home page through the link i provided.
Now the problem is, if in Step 7 i give wrong credentials and hit login button, it still directs me to the error page and from there to the home page. This should not happen.
Why is it happening like this? Why is the user credentials not validated? What is the solution for this?
Please help me out. Thanks a lot!!
Best regards Shenaz [ December 18, 2008: Message edited by: Shenaz Assu ]