On Dec 30, 2004, at 7:34 AM, Aparajita Fishman wrote:
Maybe I can do it another way, but in our system - which is a "intranet" application (high http port # etc), I use on session start to provide a first level of access control. There are areas of the system where we do not require the user to login, mainly information searches. I restrict those searched to "known" ip ranges. If a user connects from an unknown ip address, they are presented with a message that connection was make from an non-company net and they must login before even the informational areas are accessible. I do this by setting session variables in the on session start event handler, basically indicating authorized guest access or restricted guest access (login only).Hi,
In looking over my own code, I became confused as to the true purpose of On Session Start and why its presence requires that a session is implicitly created for _every_ new user that hits a site.
On Session Start is supposed to run every time a new _logical_ session is started, i.e. a user makes the first request from a site in a given browser. If a session is not created implicitly or explicitly as a result, the next request by the same user would run On Session Start again, which would kind of defeat the meaning of the event handler. Therefore a session has to be created implicitly whenever On Session Start is defined.
If a developer wants to create a standard environment for newly created sessions, but only when the user deserves a session (such as after a successful login), it should be done in a method in your own library. This is the "correct" way to handle new session creation in such situations.
THE BOTTOM LINE:
If your users don't need a session until they have successfully performed some action, DO NOT define On Session Start.
If I want to retain the restricted guest access functionality, I have to put the code somewhere. Is there a better place?
Hope this makes the issue clearer. Feel free to ask me if it isn't clear.
Steve Alex AIDT
_______________________________________________ Active4D-dev mailing list [email protected] http://mailman.aparajitaworld.com/mailman/listinfo/active4d-dev Archives: http://mailman.aparajitaworld.com/archive/active4d-dev/
