A developer is writing a server side script that needs to maintain state across calls. The persistent information needed includes these items:
* The current customer
* Whether or not the customer is authenticated
* The privacy attributes (such as tracking consent or cookie policy)
Which technique should the developer use to maintain state in an efficient and scalable manner that follows best practice?
Server-side script variables do not persist between independent request executions. B2C Commerce therefore provides theSessionobject as the appropriate request-session mechanism for maintaining shopper-specific state across calls.
Salesforce specifically identifies the Session API as providing access to thecurrent customer, whether that customer isauthenticated, session custom attributes, andcustom privacy attributes. These capabilities map directly to every requirement in the question.
A client-side cookie is inappropriate for reproducing server-maintained authentication and customer state. It would also expose application-controlled values to client modification and duplicate information already securely managed by the Commerce session. An SFRA controller does not automatically preserve its own JavaScript variables across requests; each request executes within a separate script context.
Session data should nevertheless remain lightweight. Long-lived or business-critical information that must survive beyond the shopper's browser session belongs in persistent business objects rather than session attributes. Privacy attributes have specific lifecycle semantics and are particularly appropriate for tracking consent and related shopper preferences during the active session.
Study Guide reference:Application Development --- Session API, shopper state, authentication state, privacy attributes, server-side JavaScript execution lifecycle, and scalable state management.
===============
Currently there are no comments in this discussion, be the first to comment!