[ 
https://issues.apache.org/jira/browse/SHIRO-340?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13190063#comment-13190063
 ] 

Kalle Korhonen commented on SHIRO-340:
--------------------------------------

>From my perspective, it's much more ok to assume cookies are available than 
>that the session is available. And if some users have cookies disabled 
>completely, it still works acceptably. Storing some other type of data into a 
>cookie is not necessarily the right solution, but I can't think of any reason 
>why you'd want to store an url, which is inherently string-based and fairly 
>limited in length, anywhere else than in a cookie.
                
> Shiro should avoid creating sessions if one doesn't exist
> ---------------------------------------------------------
>
>                 Key: SHIRO-340
>                 URL: https://issues.apache.org/jira/browse/SHIRO-340
>             Project: Shiro
>          Issue Type: Improvement
>          Components: Web
>    Affects Versions: 1.1.0, 1.2.0
>            Reporter: Kalle Korhonen
>
> WebUtils.saveRequest() forces creating a session even if doesn't exist 
> before. This hinders scalability. For savedRequests, it's not clear session 
> is needed at all, a cookie might be better option for storing information in 
> this case. Similarly, we should go through the rest of the codebase and see 
> if sessions are created unnecessarily.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: 
https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

Reply via email to