Controlling the session cookie?

classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

Controlling the session cookie?

Robert Nicholson-3
Does stripes allow me to set HttpOnly or Secure on the session cookie that's emitted?

Sent from my iPhone
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Stripes-users mailing list
[hidden email]
https://lists.sourceforge.net/lists/listinfo/stripes-users
Reply | Threaded
Open this post in threaded view
|

Re: Controlling the session cookie?

Rick Grashel
Hi Robert,

Stripes will not control the settings of the session cookie issued by the container.  If you are using Servlet 3.0, you can use a <session-config><cookie-config> elementsin your web.xml to set both HttpOnly and Secure.  If you are using a Servlet version less than 3.0, then you will need to probably check your container's documentation.  Most of the containers have server configuration parameters which allow for the session cookies to be set as HttpOnly and Secure.

Thanks.

-- Rick

On Wed, Jun 21, 2017 at 5:33 PM, Robert Nicholson <[hidden email]> wrote:
Does stripes allow me to set HttpOnly or Secure on the session cookie that's emitted?

Sent from my iPhone
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Stripes-users mailing list
[hidden email]
https://lists.sourceforge.net/lists/listinfo/stripes-users


------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Stripes-users mailing list
[hidden email]
https://lists.sourceforge.net/lists/listinfo/stripes-users