We have a site written in asp.net which a customer wants to provide access to for their own customers. Ok not a big issue... However, the customer wants to control access to this site through their own site written in php. The idea is that users will register on their site (hiding user/registration information from us) and will be provided with an account. When the user logs in they are provided with a link which passes the user off to our site. They also want to prevent unregistered users from accessing the site. Our first attempt at this involved checking the "referrer" was the customer?s site and setting up a session. Requests to anything other than the homepage were redirected to the customer?s website and requests to the homepage which did not come from the appropriate referrer were also redirected. Go to the complete details ...