I have a question:

I have a question:
if using a php client for datasnap and know the context and the method the method works without problem, no matter if I have or not it performs authentication, it is as if the session control was not working, if performed some control

http: // localhost: 8080 / datasnap / rest / servermethods / echoString / test does not send any session in the header and yet it performs, I know that using authorization work, then what good is the control session will have to put one in anotattion each method, it was not enough and verify who is calling this with a valid session? I have to do this manually ??? if every execution method verify that the client is sending a valid session and if this is in tdssessionmanager and not expired, has some smarter way to do ????

Comments

  1. I save sessions in a database table. And yes, every methode verify that the session is valid. its maybe not smart, but it has is advantages. Per example you can stop and restart your webserver or unload/load your ISAPI.dll's and the session is still valid. Clients where was logged in before are served without any problems.

    ReplyDelete

Post a Comment