You can send a no-cache, but nonetheless a quiet performance hit, to get what you want. I prefer the Liams offer and guarantee that everything you do from this page requires you to be logged in, so no one can do anything that they donโt need. What if its email system, although similar, people "can" view other people's emails that are cached, in these cases yes, and not caching sensitive information is the way to go (you cannot cache default HTTPS pages, for example) .
You can also include some javascript in your head that could check for a โregisteredโ cookie. This will run every time they load the page, if the cookie does not exist, then JS can redirect you to the login page. Not 100% proof of a fool, but good enough. On the logout page, you must clear this cookie and your login page is set up.
source share