Stripes will not control the settings of the session cookie issued by the container. If you are using Servlet 3.0, you can use a <session-config><cookie-config> elementsin your web.xml to set both HttpOnly and Secure. If you are using a Servlet version less than 3.0, then you will need to probably check your container's documentation. Most of the containers have server configuration parameters which allow for the session cookies to be set as HttpOnly and Secure.
On Wed, Jun 21, 2017 at 5:33 PM, Robert Nicholson <[hidden email]> wrote:
Does stripes allow me to set HttpOnly or Secure on the session cookie that's emitted?