
I perhaps don't understand you. but (!) The locale attribut has nothing to do with creating sessions! The locale attribute tells struts to save a Locale-Object in the session, if there is nothing stored.


Nicolas De Loof wrote:

Hy all,

I would like Struts NOT to create a session for an unauthentified user. As far as I 
understand Struts code, I need to
set locale="false" in struts-config.xml <controller>.

Is they're any ohter Struts mecanism that can create a session (excluding action-mapping declared as scope="session") ?

Doesn't the "locale" default value (true) expose lot's of struts application to attack 
? (server Out of Memory because
to much sessions have been created - isn't this what is called "Deny Of Service" ?)


--------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

-- =========================================== Dipl.-Inf. Manfred Wolff ------------------------------------------- phone neusta : +49 421 20696-27 phone : +49 421 534522 mobil : +49 178 49 18 434 eFax : +49 1212 6 626 63 965 33 ------------------------------------------- ____________________________________________________ Diese E-Mail enthält möglicherweise vertrauliche und/oder rechtlich geschützte Informationen. Wenn Sie nicht der richtige Adressat sind oder diese E-Mail irrtümlich erhalten haben, informieren Sie bitte sofort den Absender und vernichten Sie diese Mail. Das unerlaubte Kopieren sowie die unbefugte Weitergabe dieser Mail ist nicht gestattet.

This e-mail may contain confidential and/or privileged information. If you are not the intended recipient (or have received this e-mail in error) please notify the sender immediately and destroy this e-mail. Any unauthorised copying, disclosure or distribution of the material in this e-mail is strictly forbidden.

To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to