session id on url -- stateless cookies

C

Chip

I'm having some serrious issues with this method. I love the fact that you
don't need to worry about users not accepting cookies, but... The issue is
using the complete URL, with session id, in bookmarks and links. I thought I
had read that this wouldn't matter -- if someone bookmarked a URL, and went
to the site with an old session id embedded it would simply issue a new
session id. This doesn't happen. I've had the following problems:
* Using an incorrectly formed sessionid in the link: Resource can't be found
* Using an old session id in the link: session is timed out
* Using an old session id in the link: multiple users within the same
session -- this one is very troubling.

Please tell me if I may be doing something wrong here. These issues are
killers and I can't see how anybody can use this system when it's a security
risk.

Chip
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

No members online now.

Forum statistics

Threads
473,774
Messages
2,569,598
Members
45,150
Latest member
MakersCBDReviews
Top