Server Session,tomcat has its own session maintenance mechanism, Apache has its own session maintenance mechanism

Source: Internet
Author: User
1.SESSION generally not what you say this way of working, you open a browser, then open a, request the same URL, then one of the landing, the other one will never also login. Session and browser itself this program is linked, generally not through the IP and port to bind (if it is port and IP, browser closed session is not necessarily invalid, there is obviously a security problem, this is because of some problems of TCP protocol, it is easy to be exploited).

When the browser and the server contact, the server will send a sessionid to the browser, and then the browser record this SessionID, each time the visit will be accompanied by the ID of the past. If you want the browser to be closed after the re-open can still get, there are two aspects of the problem need to be resolved, 1 browser How to find the previous SessionID, this requires a file to record, such as the cookie,2 server can not immediately destroy the session, which I remember in Apache can be set.

2.
Session that time very good setup, different application server (java,php) have a very convenient way to set up, Baidu a search on the out. I have never heard of who set the session ID, is generally the server itself management, the original for security allocation is randomly generated, or based on the connection of the other information generated, do you intend to do a session ID pool to save session ID?

Server Session,tomcat has its own session maintenance mechanism, Apache has its own session maintenance mechanism

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.