how to refresh JSESSIONID cookie after login

前端 未结 10 1540
我在风中等你
我在风中等你 2021-01-30 17:41

A product I work on got a tough security audit by a potential customer and they are upset that Tomcat sets a JSESSIONID cookie before authentication has happened. That is, Tomc

10条回答
  •  攒了一身酷
    2021-01-30 18:25

    Is the problem that the JSESSIONID is visible in the browser or that it gets set in a cookie at all? I'm assuming it is the latter in your case.

    1.issue a new JSESSIONID cookie after login

    This is the default Tomcat behaviour if you switch from http to https at the time of login. The old one is discarded and a new one is generated.

    If your login itself is over http, I guess that's another security issue for the auditors ;)

    Or are all your pages over https?

提交回复
热议问题