Originally posted by JW Li:
Carol,
Yes, definitely would look into the code! The application was created on outdated model 1 (a lot of JAVA code handling the action embeded in JSP), and the original programmers have already left the company... I think it's the local variables defined in JSP caused the problem, but I am not sure whether my fix really makes the session data mixed up problem goes away. Even though I think it's fixed, I need some proof to make my manager happy...
Since you mention model 1 jsps: beware of use of <%! DECLARE %> tag for variables in jsps. Variables declared in this way are instance variables, not local variables. Unless the jsp is marked not
thread safe (not recommended), this can result in what appear to be mixing of user session data with concurrent users.
Good luck in setting up your tests to demonstrate the problem and then show it's fixed.