Cookieless sessions

L

Leigh

Hi

Using cookieless sessions, if a user copies a URL that
includes the embedded session ID and sends that to someone
else, i.e. via email, if that link is used within the
timeout period, they end up with the same session.

Is there a way to tell if the client using the URL and
embedded session ID is somebody different to client who
originally got the session?

Regards

Leigh
 
E

evolve

what about checking "AUTH_USER" ? in the er session variables i finks? or IP
address?
 
B

Bhaskardeep Khaund

Hi,

You can use the user IP address in a LAN scenario or toggle a database field to check the user login status.

Bhaskardeep Khaund
Hi

Using cookieless sessions, if a user copies a URL that
includes the embedded session ID and sends that to someone
else, i.e. via email, if that link is used within the
timeout period, they end up with the same session.

Is there a way to tell if the client using the URL and
embedded session ID is somebody different to client who
originally got the session?

Regards

Leigh
 
G

Guest

-----Original Message-----
Hi,

You can use the user IP address in a LAN scenario or
toggle a database field to check the user login status.
Hi

Thanks for the response. We thought about using the IP
but as this is an Intranet site, and a lot of people would
access via NAT from the same office, we would get the same
IPs from a lot of users.

Regards

Leigh
 
G

Guest

-----Original Message-----
what about checking "AUTH_USER" ? in the er session variables i finks? or IP
address?

Hi

Will take a look at this, but last time we looked at this
Server variable it was an empty string.

Regards

Leigh
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

No members online now.

Forum statistics

Threads
473,982
Messages
2,570,189
Members
46,734
Latest member
manin

Latest Threads

Top