how to refresh JSESSIONID cookie after login

前端 未结 10 1537
我在风中等你
我在风中等你 2021-01-30 17:41

A product I work on got a tough security audit by a potential customer and they are upset that Tomcat sets a JSESSIONID cookie before authentication has happened. That is, Tomc

10条回答
  •  予麋鹿
    予麋鹿 (楼主)
    2021-01-30 18:20

    If you are using Tomcat and want to apply this globally to all your servlets which use Tomcat's authentication mechanism, you can write a Valve to force this behavior, as shown in this sample code.

提交回复
热议问题