Read the rest of the thread. I agree with you completely. :-)

On Mar 21, 2007, at 11:09 PM, Neil Wilson wrote:

>
> Short answer: don't do that with cookie based sessions.
>
> Always remember what sessions are - an abstraction that gets around
> the stateless nature of HTTP. It's merely there so that you know that
> the HTTP request has come from somebody you've dealt with recently.
> That's it.
>
> It should contain the minimum amount of data necessary to identify
> where you are in the transaction sequence - assuming the information
> from the URL supplied is insufficient to do that on its own.
>
> Beyond that you are polluting the session layer with application
> concerns, for which you must expect to be smited by the Gods of
> Programming :-)
>
> NeilW
>
> On Mar 22, 2:34 am, Brad Ediger <[EMAIL PROTECTED]> wrote:
>> This discussion is about situations where confidentiality might be
>> required -- where you might want to store something in the session
>> that you don't want the user to be able to read.
>
>
> >


--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups "Ruby 
on Rails: Core" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at 
http://groups.google.com/group/rubyonrails-core?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to