Skip to content

SEC-2865: Session URL rewriting being disabled should only strip JSESSIONID #3087

@spring-projects-issues

Description

@spring-projects-issues

Rob Winch (Migrated from SEC-2865) said:

This is important so URL rewriting for something like Spring Session can take place

Things to consider:

  • Users may have customized the COOKIE name (i.e. it may be a path variable other than JSESSIONID)
  • Users may have path variables in their initial URL

Metadata

Metadata

Assignees

No one assigned

    Labels

    in: webAn issue in web modules (web, webmvc)type: enhancementA general enhancementtype: jiraAn issue that was migrated from JIRA

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions