THE BOTTOM LINE:
If your users don't need a session until they have successfully performed some action, DO NOT define On Session Start.
If I want to retain the restricted guest access functionality, I have to put the code somewhere. Is there a better place?
Steve,
We have similar needs as yours. Some pages in the site are open and others are restricted based on different criteria. Also, because our site serves multiple web applications with different access requirements, using On Session Start seemed like it would have started many sessions that would never be used.
I don't know if this is a better place, but one way to handle this is to have a library method that you can call at the beginning of any page. Pass the method some criteria such as the calling page path , have it determine based on that criteria if there are any access controls for the page, and if there are determine:
a) does a session exist, and if not does one need to be started (before or after a login?)
b) who is the current user (or is the request internal or external)
c) do they have rights to use the the page (if they don't let them know)
d) should a login page displayed
etc.
For pages where no access control is required the overhead of calling this method isn't noticeable. Of course you don't have to call it at all if it isn't needed.
It might also be possible to put the same type of logic into the On Request handler, although I've never tried that.
-- Brad Perkins
_______________________________________________ Active4D-dev mailing list [email protected] http://mailman.aparajitaworld.com/mailman/listinfo/active4d-dev Archives: http://mailman.aparajitaworld.com/archive/active4d-dev/
