| Home » Categories » Multiple Categories |
Issue with Storing Session |
|
Article Number: 301 | Rating: Unrated | Last Updated: Wed, Sep 24, 2025 at 12:08 AM
|
Sometimes, the session on your website can expire earlier than you expect. The followings are the steps you need to check:
1. In .Net, you cannot use authentication without session. The session ID can be transmitted with client either in a cookie, or in the page url. There is no need to choose between session and cookie, as the cookie actually holds the session id.
2. On the server, session data is stored either in memory (in process or outside process), or in database.
3. The cookie is encrypted using a key called the "machine key". By default, everytime the app pool is recycled, a new machine key is created and the session data that is in memory is lost. On a shared server, this results in the end of a session, since the cookie cannot be decrypted anymore.
The solution: Store a static machine key in the web.config of the web application.
Also, storing the session data in the database instead of memory (in proc) can be useful to preserve sessions.
|
Attachments
There are no attachments for this article.
|
How to Solve the error: "405 - HTTP verb used to access this page is not allowed"?
Viewed 6105 times since Wed, Oct 24, 2018
Do you allow custom COM components?
Viewed 3462 times since Tue, May 1, 2012
HTTP Error 502.5 - Process Failure error message when publishing an ASP.NET Core Website
Viewed 11480 times since Mon, Mar 27, 2017
How do I query MySQL Database in PHP ?
Viewed 3949 times since Tue, May 1, 2012
How to Solve an Error Message "Validation of viewstate MAC failed"
Viewed 10406 times since Tue, Apr 2, 2013
I cannot see my website. What should I do?
Viewed 4392 times since Thu, May 3, 2012
My site is showing 500 Internal Server error message. What is wrong here?
Viewed 4382 times since Thu, May 3, 2012
How to solve the Let’s Encrypt SSL on ASP.NET Core
Viewed 10397 times since Mon, Jul 17, 2017
Sample Code to Send email using ASP.NET 2
Viewed 10296 times since Tue, May 1, 2012
Domain Name Server (DNS) Amplification Attack
Viewed 10077 times since Wed, Oct 15, 2014
|
