I have Local Tomcat Server setup with https CorsHandler url. The tomcat server returns secure JSESSIONID cookie with the following web.xml config.