I don't understand where I am reinventing something. If the session is in the url and a session is owned by someone then if someone else uses that url he will be logged in as the original user. This is confusing from many points of view. So ideally you should split the authentication part of the session from the state part and code in the url only the state part.
To put it in other words there is a public and private part of the session and since urls are mostly treated as public you should not use urls for the private part of the session.
This is a general remark. If you want to concentrate on CGI::Session then we can analyze if it fits to this kind of usage. |