James Lin wrote:

    Yes, that will work, I got another idea by develop another shared
    plugin to write json or similar format content into a special
    named div, and use javascript to read the content from the div
    then reconstruct the variable in javascript.

Also an option, but then it's slightly easier for someone to check another user's cache dir, get the cached dokuwiki file, and play a little game of 'let's be a hacker' =)

Keeping the session variables server side is probably safer (regardless of "our users would never", it's just a better solution I would say).

- Michiel
