Skip to main content

Defective session handling

Anonymous (not verified)
Published on: 02/02/2010 Discussion Archived

Session handling is based on cookies. This should be replaced by jsessionid, thus allowing a redirection to himself.



HardwareNone
ProductNone
Operating SystemNone
ComponentOther
VersionNone
Severitymajor
ResolutionFixed

Category

Bugs

Comments

Anonymous (not verified) Tue, 02/02/2010 - 15:13

In order to turn off cookies, you must change your application server (application can't do that) configuration file. In Tomcat you have to: 1) Edit $TOMCAT_HOME/conf/context.xml 2) Change from <Context> to <Context cookies="false"> We are updating PEPS User guide in order to explain how to disable/enable cookies.