I was told this works, but...
I guess I\'m just not getting this, it seems there\'s a hidden step I may be missing, can anyone correct this or point out my mistake?
Additionally both apps must run on the same domain so that user browser use one cookie to store session id.