in reply to Re: Re: Re: Secure Session Management
in thread Secure Session Management
Sorry for the rant about E-Trust and privacy policies. Valid rant, wrong time/place.
My original point about expiring sessions by deleting cookies still holds true though.
Unless of course, the cookie was set to expire within a few minutes or hours, in which case the client won't send it. In this case, no action is required by the server to "determine a session is over" and it doesn't need to "tell the client to delete the cookie"?
My point was simply that if the session expires because the connection is broken, there is no mechanism by which the server can tell the client to delete the cookie.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Re: Re: Re: Secure Session Management
by valdez (Monsignor) on Sep 06, 2002 at 22:48 UTC |