On Sat, Feb 21, 2009 at 4:47 PM, Gustavo Narea <[email protected]> wrote:

[...]

> It's still not usual. I never said "nobody needs that".
>
> This verification on *each* request affects performance, at least slightly.
> This is why I'd prefer that people who really want it have to enable it by
> themselves... Unless there's a consensus where most people think this should
> be the default behavior.

Verification on each request will just make auth unscalable... It was
one of our issues in TG1.

> If you consider this is necessary for most people, considering the performance
> issue, I suggest that you start a new thread to start a poll. If you get
> enough support, I'll be happy to implement it by default (in TG 2.1, it's late
> for v2.0).

We should just propose an application pattern on the "remove-user"
operation to remove the session from the beaker cache so that the
cookie even if still present on the user's machine is not considered
as a valid token anymore.

Florent.

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"TurboGears" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/turbogears?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to