NOTE

1.4 How to Implement Distributed Sessions

1. What Is a Distributed Session - A session is server-side memory. - A session shared in a distributed environment (multiple machines). 2. Why Distributed Sessions Are Needed - In a distributed environment, if the traditional Tomcat session mechanism is still used, the following can happen: after a user logs in to system A, the user needs to jump to system B to perform some operations, but the user's login information is stored in system A and system B has no related session.

Distributed SystemsCreated Updated 1 min readhistorical

This is a historical learning note and may contain outdated or incomplete understanding.

1. What Is a Distributed Session?

A session is server-side memory.

A session shared in a distributed environment (multiple machines).

2. Why Are Distributed Sessions Needed?

In a distributed environment, if the traditional Tomcat session mechanism is still used, the following can happen: after a user logs in to system A, the user needs to jump to system B to perform some operations. The problem is that the user’s login information is stored in system A, while system B has no related session. At this point, system B will ask the user to log in again.

3. How to Implement Distributed Sessions

3.1. Session Replication

The disadvantage of this approach is that when there are too many machines in the cluster, session data is frequently transmitted over the network, putting heavy pressure on the network.

3.2. Single Sign-On System

That is, send all registration, login, and other user-information-related requests in the entire system to a fixed subsystem, SSO. SSO then generates a random number as a token and returns it to the client. This token is used to identify which user’s request it is.

3.2.1. Specific Implementation

The session function in the SSO system is implemented through a Redis database.

Generate a random number as the key, serialize the user information as JSON and store it in Redis. When user information is needed, retrieve it from Redis using this key.

Set the session expiration time to 30 minutes.

4. References

Spring Data Redis

Discussion

Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub