Jason Roozee
10/07/2024, 4:57 PMMark Takata (Adobe)
10/07/2024, 6:11 PMbdw429s
10/07/2024, 6:22 PMbdw429s
10/07/2024, 6:22 PMbdw429s
10/07/2024, 6:23 PMDave Merrill
10/07/2024, 6:34 PMDave Merrill
10/07/2024, 6:37 PMMark Takata (Adobe)
10/07/2024, 6:38 PMbdw429s
10/07/2024, 6:38 PMbdw429s
10/07/2024, 6:39 PMbdw429s
10/07/2024, 6:39 PMDave Merrill
10/07/2024, 6:41 PMbdw429s
10/07/2024, 6:44 PMbdw429s
10/07/2024, 6:44 PMinvalidateSession() BIF is what CF provides to force a session to go awaybdw429s
10/07/2024, 6:45 PMDave Merrill
10/07/2024, 6:46 PMbdw429s
10/07/2024, 6:46 PMbdw429s
10/07/2024, 6:49 PMExpires and Max-Age attribute. That may be the default for some types of session cookies, but I certainly wouldn't neccessarily want CF doing that out of the box. I guess it sort of goes back to who you want in control of the session expiration. The server or the client. If the web developer wants the user logged in for 2 hours, then when they come back 1 hour and 55 minutes later, they should still have a session, no?Dave Merrill
10/07/2024, 6:50 PMWe recommend using J2EE session management, if:
You want to maximize session security, particularly if you also use client variables
We don't use client variables, so maybe that don't apply, but it is their recommendation.bdw429s
10/07/2024, 6:51 PMbdw429s
10/07/2024, 6:51 PMDave Merrill
10/07/2024, 6:52 PMbdw429s
10/07/2024, 6:52 PMbdw429s
10/07/2024, 6:52 PMbdw429s
10/07/2024, 6:53 PMbdw429s
10/07/2024, 6:57 PMbdw429s
10/07/2024, 6:57 PMJason Roozee
10/08/2024, 2:46 PMJason Roozee
10/08/2024, 2:52 PMDave Merrill
10/17/2024, 3:44 PMMark Takata (Adobe)
10/17/2024, 6:34 PMDave Merrill
10/17/2024, 6:39 PM