Hi there, Is this a correct statement? I have observed difference.
CAS 4.1.x using web flow encryption to capture flow states and stores them on the client side. Therefore, even after http session expires, the flow can resume and continue. This means, I can walk away for hours, and as long as my browser is up running, I can always come back and click "Continue" to keep going. CAS 3.5.x does not do that, the flow execution key is plain text and stored in HTTP session, flow ends as session idle timeout. This means, if I walk away for hours, coming back and click "Continue", flow ends and redirect me to the starting point of the flow. Thx., Yan -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to cas-user+unsubscr...@apereo.org. To post to this group, send email to cas-user@apereo.org. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/b576db71-6aeb-4f1a-9785-55369b3407b5%40apereo.org. For more options, visit https://groups.google.com/a/apereo.org/d/optout.