On Dec 30, 2004, at 7:34 AM, Aparajita Fishman wrote:

Hi,

In looking over my own code, I became confused as to the true purpose of On Session Start and why its presence requires that a session is implicitly created for _every_ new user that hits a site.

Maybe I can do it another way, but in our system - which is a "intranet" application (high http port # etc), I use on session start to provide a first level of access control. There are areas of the system where we do not require the user to login, mainly information searches. I restrict those searched to "known" ip ranges. If a user connects from an unknown ip address, they are presented with a message that connection was make from an non-company net and they must login before even the informational areas are accessible. I do this by setting session variables in the on session start event handler, basically indicating authorized guest access or restricted guest access (login only).

On Session Start is supposed to run every time a new _logical_ session is started, i.e. a user makes the first request from a site in a given browser. If a session is not created implicitly or explicitly as a result, the next request by the same user would run On Session Start again, which would kind of defeat the meaning of the event handler. Therefore a session has to be created implicitly whenever On Session Start is defined.

If a developer wants to create a standard environment for newly created sessions, but only when the user deserves a session (such as after a successful login), it should be done in a method in your own library. This is the "correct" way to handle new session creation in such situations.

THE BOTTOM LINE:
If your users don't need a session until they have successfully performed some action, DO NOT define On Session Start.

If I want to retain the restricted guest access functionality, I have to put the code somewhere. Is there a better place?

Hope this makes the issue clearer. Feel free to ask me if it isn't clear.


Steve Alex
AIDT

_______________________________________________
Active4D-dev mailing list
[email protected]
http://mailman.aparajitaworld.com/mailman/listinfo/active4d-dev
Archives: http://mailman.aparajitaworld.com/archive/active4d-dev/

Reply via email to