httpservletrequest - create new session / change session Id

I'm maintaining a Java web application. Looking into the login code it gets an HttpSession out of HttpServletRequest via the getSession() method of HttpServletRequest. (It uses some values in the session for authentication purposes) However I'm worried about session fixation attacks so after I have used the initial session I want to either start a new session or change the session id. Is this possible?

以上就是httpservletrequest - create new session / change session Id的详细内容,更多请关注web前端其它相关文章!

赞(0) 打赏
未经允许不得转载:web前端首页 » JavaScript 答疑

评论 抢沙发

  • 昵称 (必填)
  • 邮箱 (必填)
  • 网址

前端开发相关广告投放 更专业 更精准