State Server Session - Cross AppDomain?

When using a state server for a session, are sessions still application specific? So, for example, I have two different IIS applications (virtual directories) on a web server and they both point to the same state server for the session. The session guidance from the cookie will be the same in the requests of both applications, and will the same session be available to both of those applications? Thanks.

+2


a source to share


2 answers


As @ntziolis mentioned in his answer, and @Aristos mentions in his comment, the session is based on a combination of the application name and the session cookie. You can get it to work (as I did) if the application name matches and the session cookie value matches.

To get the application name the same, I used this solution from SO using reflection:

protected void Application_Start(object sender, EventArgs e)
{
    string applicationName = "MySiteName";

    // Change the Application Name in runtime.
    FieldInfo runtimeInfo = typeof(HttpRuntime).GetField("_theRuntime", BindingFlags.Static | BindingFlags.NonPublic);
    HttpRuntime theRuntime = (HttpRuntime)runtimeInfo.GetValue(null);
    FieldInfo appNameInfo = typeof(HttpRuntime).GetField("_appDomainAppId", BindingFlags.Instance | BindingFlags.NonPublic);

    appNameInfo.SetValue(theRuntime, applicationName);
}

      

I added this both to the Global.asax files (of each of my sites).



To make the session cookie the same, the cookie cannot be invalid because of the path or domain. If you have two virtual directories under the same site, you are good at understanding the cookie path and domain.

Unless you add explicit code to your web.config file, the session cookie name and machine key will also be the same by default. If not, you need to make sure yours is <machineKey>

explicitly set and the same between the two apps, and the value for cookieName

in is <sessionState>

explicitly set and the same between the two apps:

<configuration>
  <system.web>
    <machineKey validationKey="77D2713C3E6C46160F278B7F4787A341A8E9010C3C228F8E9522685050F5204ECA0F2BA2169C4F29C1ADD8C3B99E7143A21272A59373BFBEF21C6677D0FF293C" decryptionKey="286F0EA94D5DA2E697C8C148934EF885A6513AD91C044EDFE7DC45027653B830" validation="SHA1" decryption="AES" />
    <sessionState cookieName="mySessionCookie" mode="StateServer" stateConnectionString="tcpip=127.0.0.1:42424" cookieless="false" timeout="20" />
  </system.web>
</configuration>

      

This worked for me - I was able to create a proof of concept website for this.

+2


a source


The problem is not appDomain, but the application name (in the web.config file). If the application name is the same, you should be able to share the session state.



For different app names check here .

0


a source







All Articles