Clientside stuff is easy to hack. Letting them to handle server-related security stuff is certainly bad practice.
And now I guess that kannankalli just want to prevent others from accessing restricted pages. But he actually has implemented completely nothing to accomplish that and was expecting of some magic. Is that true, kannankalli? Or did you actually have implemented kind of a Filter to block that? If so, then please elaborate the detailed problem with the filter. If not, first implement it yourself, then we'll see further. Or if you don't know how to implement it, then please ask specific questions. You're the developer here, not us.