Re: [Acegisecurity-developer] Changing the session identifier after a successful login

2006-09-28 Thread Ben Alex
Twomey, Sean wrote: > Our application has just recently integrated acegi as our security > framework. However we now have a requirement to change the session > identifier (JSESSIONID) after a successful login, since this session id is > issued at/before the login page, and is thus prone to session

[Acegisecurity-developer] Changing the session identifier after a successful login

2006-09-28 Thread Twomey, Sean
Title: Message Hi all,   Our application has just recently integrated acegi as our security framework. However we now have a requirement to change the session identifier (JSESSIONID) after a successful login, since this session id is issued at/before the login page, and is thus prone to se