Invalidating session on

By commenting, you are accepting the IBM commenting guidelines and the DISQUS terms of service.I need to find a way to invalidate the session when the user closes the browser.

Maybe the ICEfaces developers could clarificate how to face this kind of stuff. The server will invalidate your session anyway after X minutes of inactivity.

People tend to forget that HTTP protocol is STATELESS.

In fact one framework is not more secure than another: If you use it correctly, you will be able to build secure apps with many frameworks.

Ruby on Rails has some clever helper methods, for example against SQL injection, so that this is hardly a problem.

We are currently calling a servlet from a javascript function that is called via the onunload function.