|
Client-based solutions - like _javascript_ - will only work if
security is not important. Folks who wish to bypass client scripting
and make another http request will be able to do so by manipulating
a client device; thus extending a CFML session. CFML Sessions are designed to be extended whenever another request is made (no http request - new page, reload page, httpAsync request, whatever). They are designed to expire only after a period of inactivity - as in no request at all. You'll need a separate (session) variable (in a session which lasts longer than your special test) or cookie, which stores a datetime from their last request, so only you can update it, and you can do your own security magic with it. If THAT time has passed, or the parameter is missing entirely, then force your logout. Al Holden On 6/25/2014 1:29 PM, Marcus F wrote:
-- -- online documentation: http://openbd.org/manual/ http://groups.google.com/group/openbd?hl=en --- You received this message because you are subscribed to the Google Groups "Open BlueDragon" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout. |
- [OpenBD] Detect Page Reload Skellington
- [OpenBD] Re: Detect Page Reload Marcus F
- Re: [OpenBD] Detect Page Reload Ernest McCloskey
- Re: [OpenBD] Detect Page Reload Marcus F
- Re: [OpenBD] Detect Page Re... 'Alan Holden' via Open BlueDragon
- Re: [OpenBD] Detect Pag... Marcus F
- Re: [OpenBD] Detec... Ernest McCloskey
- Re: [OpenBD] D... 'Alan Holden' via Open BlueDragon
- Re: [OpenB... Ernest McCloskey
- Re: [OpenBD] Detect Pag... Skellington
