| |
|
- The only page that can be freely accessed is the login page.
- When a log on is successful a new session is created and an unique
access key is assigned to the session.
- Each request to the WebConnect site must contain this unique access
key.
- The access key is verified before any processing takes place.
- A user's session is ended when the user logs out or after the session
times out.
- Once a session is destroyed, links on cached or bookmarked pages are
no longer valid and can't be used by other persons to read your private
mail.
|