Aparajita,

You made this really clear to me at the Summit and it solved the problem I was having of a kind of DOS attack where a client/browser/robot was continually requesting the first page that triggered the "On Session Start" method and thus created a session, due to my code therein. But since they were refusing cookies and I only tracked sessions with cookies, each attempt would start a new session ad infinitum until such time as the 4D Application ran out of memory. Based on the fact that my session expires was set to 15-30 minutes depending on the page.

I am replacing this as per your suggestion with no session created until such time as successful login occurs.

thanks for restating it again for me and everyone else...

gary


On Dec 30, 2004, at 8:00 AM, [EMAIL PROTECTED] wrote:



THE BOTTOM LINE: If your users don't need a session until they have successfully performed some action, DO NOT define On Session Start.

Hope this makes the issue clearer. Feel free to ask me if it isn't
clear.

Regards,

    Aparajita
    Victory-Heart Productions
    www.aparajitaworld.com


------------------------------------------------------------------------
Gary Pedretty                                    [EMAIL PROTECTED]
Systems Manager                                   www.frontierflying.com
Frontier Flying Service, Inc.         /\                    907-450-7251
5245 Airport Industrial Road         /  \/\             907-450-7238 fax
Fairbanks, Alaska  99709        /\  /    \ \ Second greatest commandment
Serving Alaska's Interior      /  \/  /\  \ \/\   "Love your neighbor as
Temperature around +10 and snowy skies              yourself" Matt 22:39
------------------------------------------------------------------------

_______________________________________________
Active4D-dev mailing list
[email protected]
http://mailman.aparajitaworld.com/mailman/listinfo/active4d-dev
Archives: http://mailman.aparajitaworld.com/archive/active4d-dev/

Reply via email to