Ok, I think I understand what's going on now. The way forms authentication works is that it will allow users into the site if they are valid. If not, then they will be redirected back to the login page. In addition, if they have become idle or the session/cookies have timed out, then when they try to execute something on the page, it will bring them back to the login page. Is that correct?
Normally session/cookies is reset when the page is being processed, right?
|