how to prevent user from direct url entering