how to refresh JSESSIONID cookie after login

前端 未结 10 1538
我在风中等你
我在风中等你 2021-01-30 17:41

A product I work on got a tough security audit by a potential customer and they are upset that Tomcat sets a JSESSIONID cookie before authentication has happened. That is, Tomc

10条回答
  •  抹茶落季
    2021-01-30 18:14

    HttpServletRequest.changeSessionId() can be use to change the session ID at any point of time.

提交回复
热议问题