Category:WASS Authentication Identifer

Revision as of 23:33, 18 May 2006 by MikeAndrews (Talk | contribs)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search

Establish a new session identifier upon user authentication

A session identifier is a way to keep track of an authenticated session. Reusing a session identifier that was available before authentication could provide a user a means of discoving a users authenticated session identifier value.

1. A new session identifier should be created when a user is authenticated and when their role/privilage changes in the application

This category currently contains no pages or media.