This week's book giveaway is in the Servlets forum.
We're giving away four copies of Murach's Java Servlets and JSP and have Joel Murach on-line!
See this thread for details.
The moose likes Servlets and the fly likes Session question Big Moose Saloon
  Search | Java FAQ | Recent Topics | Flagged Topics | Hot Topics | Zero Replies
Register / Login


Win a copy of Murach's Java Servlets and JSP this week in the Servlets forum!
JavaRanch » Java Forums » Java » Servlets
Bookmark "Session question" Watch "Session question" New topic
Author

Session question

Stephen Wei
Ranch Hand

Joined: Oct 09, 2001
Posts: 73
Hi I have a stupid question.
Does Session continue when access a different web server in a different site?
The think I am worrying is that: what if someone creates a jsp page on the local web server, then creates a session and all the input variables in it, then can he access to my servlet on my server with out login? I plan to use my login.jsp to create a session, then add "user" attribute to the session, then all my servlet and Jsp will check for the "user" Session attribute, if null, return to the login.jsp.
But can someone creates the session and session attribute on his own server, then access my servlet without login?
Thanks!


Sun Certified Programmer for Java Platform
Eric lau
Greenhorn

Joined: Jan 21, 2002
Posts: 27
No problem,session is maintained by the web server,if he did not log in ,he cant pass your check with his session on his web server!


I come from China
Stephen Wei
Ranch Hand

Joined: Oct 09, 2001
Posts: 73
Hello Mr Liu HongWei!
Thanks for your answer, that really helps. Now I can continue with my current approach.
Stephen Wei
 
With a little knowledge, a cast iron skillet is non-stick and lasts a lifetime.
 
subject: Session question
 
Similar Threads
How does jSecurityCheck know which page was requested ?
Maintaining sessions
MVC, JSP/Servlet/Bean Design Issue
Session is not working
call an action from another module in getRequestDispatcher()?