Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
1.2.6
-
None
-
None
Description
The tomcat 7 plugin doesn't handle changes of session ids. E. g. during the login phase of the container the session id changes (when session fixiation protection is not disabled). Such changes are not propagated to the session context manager, which uses the session id to identify the current session context. Hence a new session context is created.