Um, now about using tokens? Support is built-in after all. Regards, David
-----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: Wednesday, October 05, 2005 8:42 AM To: user@struts.apache.org Subject: encoding the session Hi, Can anyone advise on how to encode the session Id so that a user cannot just type in the URL and get to the jsp? For example my user can create a client form creatClient.jsp but can also go straight to the editClient.jsp by adding it to the URl and I want to stop this Thanks --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED] --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]