A normal user can login and logout and write new messages, that's fine. The only issue is now that every user has got admin rights. That means that the "admin option" link is displayed and also the full set of icons.
to which asp-file and code-line should I focus?
I reset the inc_header.asp to the original version but that was maybe not enough.