in reply to logging the user once every session

It doesn't happen too often, but what about load balanced proxying? My company produces an application taht can't deal with that sorta thing. Neither will yours in this case if you do that.

On load balanced proxies, it's typical for the least heavily loaded proxy to deal with your request. At some point, AOL did this. I advise you not do this and just use cookies instead. If you are really worried about security, a dedicated connection via a desktop application, instead of connectionless http, might be prefered.

  • Comment on Re: logging the user once every session