At 08:39 25.05.2001 +1200, you wrote:

>And there lies the rub.
>The user is using the system to process client A. The cookie contains
>stateful information including the client ID.
>They then open an new browser window, and lookup client B, recieving a
>new session ID with new state information, including the client ID.

Why are you doing this. client B probably sends a valid session ID, so why 
does he get a new one?

>(Oh and telling the users 'Don't Do That' does not work either :^)

Never does.


"... ein Geschlecht erfinderischer Zwerge, die fuer alles gemietet werden
koennen."                            - Bertolt Brecht - Leben des Galilei

Reply via email to