| If you use the userreferenceargument, this is inevitable. Consider this scenario: I hit a page and send a link to someone - I'm copying the URL, arguments and all. If the person hits the URL before the session expires, we're sharing a session. I've seen this happen (before we nuked userreferenceargs ) where a chain is set up and people are joining a common session. A variation on this is someone sending a URL out to a list or posting it someplace. It's easy to have shared sessions. Party lines, if you will. Appending random numbers won't cure this. It's not a cache issue. Roland A. Dumas 310 W. Bellevue Ave. San Mateo, CA 94402 650-347-1373 415-412-9300 (cell) AIM: radumas On Aug 24, 2005, at 12:26 PM, Alan Wolfe wrote:
________________________________________________________________________ TO UNSUBSCRIBE: Go to http://www.witango.com/developer/maillist.taf |
- Witango-Talk: Inadvertant session highjacking? Alan Wolfe
- Re: Witango-Talk: Inadvertant session highjacking? Bill Conlon
- Re: Witango-Talk: Inadvertant session highjacking? Roland Dumas
- Re: Witango-Talk: Inadvertant session highjacking? Alan Wolfe
- Re: Witango-Talk: Inadvertant session highjackin... Roland Dumas
- RE: Witango-Talk: Inadvertant session highjackin... Ian Daniel
- RE: Witango-Talk: Inadvertant session highja... Peter Dobbs
