Isn't the idea to leave the cookies as they are, but destroy the session and it's contents?
I always liked the fact that the user has the same CFID etc. upon every visit. I guess the issue you guys are having is that the user could be using a public terminal. What about "I am on a public temrinal" checkbox??? -----Original Message----- From: Gary Menzel [mailto:[EMAIL PROTECTED] Sent: Thursday, 13 November 2003 9:36 AM To: CFAussie Mailing List Subject: [cfaussie] RE: sessions won't go away > that makes sence but is it the best way to do this (best practice) - to > counteract the "stickyness"? I don't know of any other way to do it. This is because CF originally creates the cookies for you behind the scenes and sets the expiry to NEVER. So you have to throw in a bit of code to "undo" it. Here is a slighter shorter form that doesn't require intermediate variables: <!--- set session coookies ---> <CFIF StructKeyExists(cookie,"cfid") and StructKeyExists(cookie,"cftoken")> <CFCOOKIE name="cfid" value="#cookie.cfid#"> <CFCOOKIE name="cftoken" value="#cookie.cftoken#"> </CFIF> We also additionally add in a check to see that the logged in user for the Session is the same as the last user for that same session and, if not, we expire BOTH sessions. This means that someone may have to log in twice, but absolutely ensures that sticky sessions are completely demolished. Gary Menzel Web Development Manager IT Operations Brisbane -+- ABN AMRO Morgans Limited Level 29, 123 Eagle Street BRISBANE QLD 4000 PH: 07 333 44 828 FX: 07 3834 0828 **************************************************************************** If this communication is not intended for you and you are not an authorised recipient of this email you are prohibited by law from dealing with or relying on the email or any file attachments. This prohibition includes reading, printing, copying, re-transmitting, disseminating, storing or in any other way dealing or acting in reliance on the information. If you have received this email in error, we request you contact ABN AMRO Morgans Limited immediately by returning the email to [EMAIL PROTECTED] and destroy the original. We will refund any reasonable costs associated with notifying ABN AMRO Morgans. This email is confidential and may contain privileged client information. ABN AMRO Morgans has taken reasonable steps to ensure the accuracy and integrity of all its communications, including electronic communications, but accepts no liability for materials transmitted. Materials may also be transmitted without the knowledge of ABN AMRO Morgans. ABN AMRO Morgans Limited its directors and employees do not accept liability for the results of any actions taken or not on the basis of the information in this report. ABN AMRO Morgans Limited and its associates hold or may hold securities in the companies/trusts mentioned herein. Any recommendation is made on the basis of our research of the investment and may not suit the specific requirements of clients. Assessments of suitability to an individual's portfolio can only be made after an examination of the particular client's investments, financial circumstances and requirements. **************************************************************************** --- You are currently subscribed to cfaussie as: [EMAIL PROTECTED] To unsubscribe send a blank email to [EMAIL PROTECTED] MXDU2004 + Macromedia DevCon AsiaPac + Sydney, Australia http://www.mxdu.com/ + 24-25 February, 2004 --- You are currently subscribed to cfaussie as: [EMAIL PROTECTED] To unsubscribe send a blank email to [EMAIL PROTECTED] MXDU2004 + Macromedia DevCon AsiaPac + Sydney, Australia http://www.mxdu.com/ + 24-25 February, 2004
