This week's giveaway is in the Android forum.
We're giving away four copies of Android Security Essentials Live Lessons and have Godfrey Nolan on-line!
See this thread for details.
The moose likes Beginning Java and the fly likes session implementation Big Moose Saloon
  Search | Java FAQ | Recent Topics | Flagged Topics | Hot Topics | Zero Replies
Register / Login

Win a copy of Android Security Essentials Live Lessons this week in the Android forum!
JavaRanch » Java Forums » Java » Beginning Java
Bookmark "session implementation" Watch "session implementation" New topic

session implementation

Pradip Bhattacharya

Joined: Dec 05, 2008
Posts: 23
I am not sure whether this is the right place to post this question or not.

I need to make a client-server application where the client will log in for some service. Whenever the client logs in the server will provide a unique number to the client, this number will help the server to identify a client. I was wondering what would be the best way to generate this unique number. Should I use IP address of the client to generate this number or not. Please do let me know about your ideas/suggestion and if possible any good literature that I can refer to.

Eric Pascarello

Joined: Nov 08, 2001
Posts: 15376
Programming Diversions is for fun questions/quizes.

Will move your question to JIG Beg. where they can talk about GUIDS with you.

Campbell Ritchie

Joined: Oct 13, 2005
Posts: 38045
Don't know. But you can have several people from the same IP and the same person can have several IPs, so I don't think IPs will work.
Pradip Bhattacharya

Joined: Dec 05, 2008
Posts: 23
how can same person have multiple IPs ?
K. Tsang

Joined: Sep 13, 2007
Posts: 2247

Well depends on how you look at it. A computer indeed only has one IP address. But from the application viewpoint, if say you allow 2 different users to log in at the same time on the same computer ... voila IP generated session ID will crash.

A better approach may be to use the hashcode of the username and password.

Campbell Ritchie

Joined: Oct 13, 2005
Posts: 38045
You are right about two people with the same IP, K Tsang. Thank you. We also have people here on JavaRanch whose IP changes from time to time; presumably they log in on different computers.
A hash, however, risks collisions; it is only a matter of time before two people have the same hash.
I agree. Here's the link:
subject: session implementation
Similar Threads
window without menu bar ...
how to generate unique number?
distinguishing 2 browsers in the same session.
Distinct ID
How do you uniquely identify a user of a midlet on a server?