0
votes

I'm hoping to get some ideas on handling session timeouts in coldfusion.

Right now, when a user logs in, I set session.LoggedIn to true, then of course, when the session times out, that changes to false. All of my coldfusion pages are coded to check for this variable and if it's false, it redirects to and Access Denied page. I changed that code to redirect to index.cfm where their credentials are validated and they're redirected back to their home page. The problem with doing it this way, is if they are in one of their applications and their session expires, when they click on something, they get taken back to their home page.

I tried using a cflocation tag in the OnSessionEnd function in Application.cfc, but of course that didn't work. It's not a real critical issue but I was hoping I could get some ideas from the forum on how you handle this in your environments.

Thanks

1
First, this is not a forum. It is a question and answer site. Second, you should provide us with some of your code so that we can better assist you in finding an answer to your specific question. - Evik James
All your ColdFusion pages are coded to check for this variable? Sounds like a lot of repetitive code. Are you familiar with the onRequestStart function in Application.cfc? Also, when the session times out, the session scope will probably be empty, so relying on session.LoggedIn being equal to false might not work as well as you had hoped. - Dan Bracuk
toleolu - The reason for mentioning the Q&A site distinction is that Stack Overflow has a different set of rules than you might expect if you are coming from a discussion forum. While the above is certainly a valid question, "as written" it could be viewed as "off-topic" and potentially closed. Typically questions should include a bit of code demonstrating the issue, like in your previous questions. Just mentioning it so it does not take you by surprise. - Leigh

1 Answers

1
votes

The SESSION scope is renewed on every page click, or access of the SESSION scope. So, if you have a session timeout set to 10 minutes, and they refresh their page every nine minutes, their session is renewed. They will never be timed out.

The session timeout doesn't start from the time the session is created.