From: Rich Kilmer Date: 2002-02-14T14:19:05+09:00 Subject: RE: IOWA troubles (was Re: choice of HTML templating system) > My god, you're right... I can't believe I actually advocated frames... > where's that soap, I feel dirty! :) Actually, I didn't really > *advocate* it, just pointed out that you could do it if you cared about > the URI's :) > > I notice I deleted your comment about security which I meant to reply > to. I agree this is a problem. We intend to add support for > authentication which would help a little (for expired sessions, etc), > and not showing the session-id in the URI (ie. putting it in a cookie) > also helps at some level. We've also thought about storing the IP > address of the user and only allowing connections to their session from > that IP. Obviously all these items have pros and cons and need to be > configurable. If you have any other ideas that would help please > mention them. We haven't really adressed this yet but we should. > > In closing, I should reiterate that Iowa is great for designing web > *applications* but not so great for desiging web *sites*. I keep > thinking we should be writing our web site using Iowa as a proof of > concept, but I don't think it works very well - for the exact reason > that you want to be able to bookmark it... it isn't really an > application, just a bunch of static, or quasi-dynamic content. > > Phew, long message, hope it clarifies some, > > Julian > > -- > julian@beta4.com > Beta4 Productions (http://www.beta4.com) On a project I was on we created a session token that consisted of this: