@Jorge 00:04 Nov 27, 2011
It is not clear whether the text refers to:
a) an authorization given to a user which remains valid for any amount of access during a predetermined period of time, e.g. 1 month, for temporary authorization to a student getting work experience;
b) an authorization which is maintained from the moment when a user logs into the system until (s)he logs out, or until there is no keyboard activity for a determined period of time.
Zep's first proposal is OK for the first configuration, his second option is better in the second case (where the system remains active through the use of 'session variables'). |