On Sat, Feb 21, 2009 at 4:47 PM, Gustavo Narea <[email protected]> wrote:
[...] > It's still not usual. I never said "nobody needs that". > > This verification on *each* request affects performance, at least slightly. > This is why I'd prefer that people who really want it have to enable it by > themselves... Unless there's a consensus where most people think this should > be the default behavior. Verification on each request will just make auth unscalable... It was one of our issues in TG1. > If you consider this is necessary for most people, considering the performance > issue, I suggest that you start a new thread to start a poll. If you get > enough support, I'll be happy to implement it by default (in TG 2.1, it's late > for v2.0). We should just propose an application pattern on the "remove-user" operation to remove the session from the beaker cache so that the cookie even if still present on the user's machine is not considered as a valid token anymore. Florent. --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "TurboGears" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [email protected] For more options, visit this group at http://groups.google.com/group/turbogears?hl=en -~----------~----~----~----~------~----~------~--~---

