You can't really prevent sessions from being used by sub-directory (that I know of), but per-domain you can. One thing you could do is add a new session variable called "domain" which holds the application name. If the session variable has a value of "app1" and they're in "app2", then kill and regenerate a new session for them. Otherwise, continue using the same one.