Session object and SessionID in Classic ASP

The Classic ASP Session object stores per-visitor values on the server between requests. Typical uses include a signed-in user ID, a short-lived preference, or workflow state that must survive navigation from one ASP page to another.

Session state is different from query strings and form fields because those values travel with individual requests. The server associates session state with a session identifier maintained by ASP.

Read the ASP session identifier

Response.Write Session.SessionID

Treat the session identifier as implementation detail. Do not print it on production pages or use it as a public account identifier.

What belongs in a Session?

Keep only user-specific, short-lived state in Session. Site-wide announcements and other shared information belong in application configuration, a database, cache, or another shared store.

Server resources and timeout

Session values live on the server, so large objects or excessive per-user state consume memory. Store compact values such as IDs rather than whole recordsets or large data structures. Classic ASP session state is enabled by default in IIS and the default timeout is 20 minutes unless the server configuration or application changes it.

Security considerations

Server-side storage does not make every value automatically safe. Do not store a user's plaintext password in Session. Use HTTPS, keep authentication state minimal, validate authorization on protected pages, and avoid exposing the session identifier in URLs or page output.


ASP Home






✖
We use cookies to improve your browsing experience. . Learn more
HTML MySQL PHP JavaScript ASP Photoshop Articles Contact us
© 2000-2026 plus2net.com All rights reserved worldwide Privacy Policy Disclaimer