[ https://issues.apache.org/jira/browse/FELIX-5099?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Work on FELIX-5099 started by David Bosschaert. ----------------------------------------------- > JSESSIONID Cookie in HTTPS Session Without 'Secure' and ‘HttpOnly’ Attributes > ----------------------------------------------------------------------------- > > Key: FELIX-5099 > URL: https://issues.apache.org/jira/browse/FELIX-5099 > Project: Felix > Issue Type: Bug > Components: HTTP Service > Reporter: Antonio Sanso > Assignee: David Bosschaert > Attachments: FELIX-5099-patch.txt > > > The session Cookie JSESSIONID has not the attributes HttpOnly and Secure; > There is already a pull request to address the HttpOnly case in > https://github.com/apache/felix/pull/12/files > Same approach can be used to address the secure flag -- This message was sent by Atlassian JIRA (v6.3.4#6332)