Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
Description
The session Cookie JSESSIONID has not the attributes HttpOnly and Secure;
There is already a pull request to address the HttpOnly case in https://github.com/apache/felix/pull/12/files
Same approach can be used to address the secure flag