Question on authentication?

For "tests", how would the user always know that the session has timed out 
for them, and that
the user is not currently authenticated?  Would the user always be able to 
tell unambiguously
whether or not they are in the "authenticated" or "non-authenticated" state 
with respect to a
session?

Thanks and best wishes
Tim Boland NIST


At 02:41 PM 2/21/2006 +1100, you wrote:


>Hi,
>
>Please have a look at and provide responses for:
>
>* If users submit data when the user is no longer authenticated, the
>data is saved and the data is reused after the user re-authenticates
><http://tinyurl.com/8qda2>
>
>Tim - please feel free to explain anything you think I may have
>misinterpreted.
>
>Thanks
>Sofia

Received on Tuesday, 21 February 2006 14:51:23 UTC