Hi
How can I change the value of the JSESSIONID cookie after
succcessfull login - failure to do this will result in a session
hijacking vulnerability.
I'm not using Spring or AECGI (sp?) and am not interested in it at the moment.
In tapestry 5.0 the value of the cookie (somewhat magically and
unexpectedly) changed when a new instance of my SessionState object
was created: e.g.
@SessionState
private MerchantState merchantState;
public void resetState(...) {
merchantState = null;
merchantState = new MerchantState();
...
}
With tapestry 5.1.0.5 The cookie value now remains the same.
Thanks
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]