You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@openwebbeans.apache.org by "Mark Struberg (JIRA)" <ji...@apache.org> on 2015/04/12 21:14:12 UTC

[jira] [Resolved] (OWB-1041) Session id changes in tomcat integration are not propagated to session context manager

     [ https://issues.apache.org/jira/browse/OWB-1041?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Mark Struberg resolved OWB-1041.
--------------------------------
       Resolution: Fixed
    Fix Version/s: 1.5.0
         Assignee: Mark Struberg

> Session id changes in tomcat integration are not propagated to session context manager
> --------------------------------------------------------------------------------------
>
>                 Key: OWB-1041
>                 URL: https://issues.apache.org/jira/browse/OWB-1041
>             Project: OpenWebBeans
>          Issue Type: Bug
>    Affects Versions: 1.2.6
>            Reporter: Sebastian Gebhardt
>            Assignee: Mark Struberg
>             Fix For: 1.5.0
>
>         Attachments: OWB-1041.patch
>
>
> The tomcat 7 plugin doesn't handle changes of session ids. E. g. during the login phase of the container the session id changes (when session fixiation protection is not disabled). Such changes are not propagated to the session context manager, which uses the session id to identify the current session context. Hence a new session context is created.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)