Is it possible to block iframe's contents for calling from browser alone?
For example;
domain.com/index.php has iframe.php in it.
index.php
has session also iframe.php has. But when session start, user can call iframe.php as
domain.com/iframe.php