re: session timeout
Christian Cabanero <chumpboy-/[email protected]> Mon, 11 Nov 2002 09:49:29 -0800 (PST)
| Newsgroups | gmane.comp.java.securityfilter.user |
|---|---|
| Message-ID | <[email protected]> |
Hello, First off, let me just say that I'm really glad I found the securityfilter project on sourceforge! I'm trying to determine if securityfilter stores info in the user's session so that it doesn't have to actually invoke all the security checking once a user has already logged in. From looking at the code, is that what the ALREADY_PROCESSED attribute is for? So if it finds this set to "true" in the user's session it'll bypass the security check? I noticed in the code that the attribute is set at the request level and not the session level as I would have assumed. Would this mean that the security check would get invoked with every new request? If so, is this so that it can check the user's role against the protected resource as well? My main concern is that explicitly invoking a security check for every request might slow things down. Thanks for any help, Christian __________________________________________________ Do you Yahoo!? U2 on LAUNCH - Exclusive greatest hits videos http://launch.yahoo.com/u2 ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf