Hi

Is it safe to use the same session ID for HTTP and HTTPS? If not then
how can I deal with a situation where the users disabled cookie and
access to the protected resources? If I don't use the same session ID,
they need to login every time when they access to the protected
resources as the login page uses HTTPS and other pages use HTTP.

Thanks

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to