
Adobe documentation - Confidential
Mechanism for
Client Sessions
If applications have client
management enabled a large
amount of data can accumulate on
the server. This can lead to a
storage failure if disks become full.
Because the registry is typically
located on the system partition it is
not recommended to use the
Server Settings > Memory Variables
variables
interoperability
required.
When checked ColdFusion will use
the session management of the
underlying JEE container (eg
Tomcat) instead of it
’s own
CFID/CFTOKEN.
When J2EE sessions are enabled
certain features such as application
specific session cookie settings
(this.sessionCookie in
Application.cfc) do not apply. The
functions SessionRotate and
SessionInvalidate do operate on
Variables
not using sessions
Most applications require session
variables but if none of the
applications on the server require
Session Variables
Two days is generally too long for
sessions to persist. Lower session
timeouts reduce the window of risk
Session Variables
Twenty minutes is a good default
value, but high security applications
will require a lower timeout value.
Adobe documentation - Confidential
Comentários a estes Manuais