Spring Security Sessions without cookies

后端 未结 4 2078
天命终不由人
天命终不由人 2020-12-06 04:24

I\'m trying to manage sessions in Spring Security without leveraging cookies. The reasoning is - our application is displayed within an iframe from another domain, we need t

4条回答
  •  予麋鹿
    予麋鹿 (楼主)
    2020-12-06 05:03

    You can have a token based communication between the site DomainB.com server and the client browser. The token can be sent from the DomainB.com server in the response's header , after authentication. The client browser can then save the token in localstorage/session storage (have a expiry time too). The client can then send the token in every request's header. Hope this helps.

提交回复
热议问题