The problem here is that you cannot read the expiration date of the cookie so that you do not know from cookies that are old users.
So your options are:
- If you can find out which of the "old" versions, you have the logic to expire your cookie.
- Force logout once if they donβt have a cookie named VersionLogout. After you are forced to log out, set a cookie named "VersionLogout" with a value of 1.2, for example, so you know that you are forced to log out of the system for a specific version, and they (in the future) will no longer be be requested.
You put this code in the Application_AuthenticateRequest event in global.asax. At this point, the user is authenticated so that you can verify their cookie.
source share