in reply to Re: CGI Session 'security' for in-house app.
in thread CGI Session 'security' for in-house app.
HTTP authentication does not, to my knowledge, facilitate expansion to session data management. This is also the reason for the expiration time. The short duration is simply based on the expected usage patterns. Not using any expiration time would allow the possibility - admittedly remote - of reuse (by regeneration) of the session key. It's simply a means to keep the database 'clean'.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: CGI Session 'security' for in-house app.
by Abigail (Deacon) on Jul 06, 2001 at 01:34 UTC |