Skip to main content

[webtier] Re: http session lost when switching from https to http (on cluster)

1 reply [Last post]

Reply viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
Jan Luehe

Hi Adam,

On 02/26/09 10:56 AM, wrote:
> Hi Jan,
> thanks for answer, it is exactly as you wrote.
> I have found that I can force JSESSIONIDVERSION to be always unsecure (in sun-web.xml) and this solves my problem,
Great! Glad you figured this out as a possible workaround!
> however isn't it strange behaviour?
> I mean, if JSESSIONID is marked properly why JSESSIONIDVERSION is not?
Because unlike the JSESSIONID cookie, which is appended only to the first
response (since it will never change from then on), the JSESSIONIDVERSION
cookie is appended to every response, as its value is incremented for
each request,
and the default behaviour for cookies is to inherit the security setting
of the request.

> My scenario is quite popular, home page, login using secure connection and go back to home page or other pages which can be unsecure. With, I guess, standard behaviour of JSESSIONIDVERSION it will always fail.

Would you mind filing an issue in the GlassFish IssueTracker under the
category and assign to jluehe?

BTW, which version of GlassFish are you using?



> Nevertheless, thanks for your help.
> Regards,
> Adam
> [Message sent by forum member 'adeboinfo' (adeboinfo)]
> ---------------------------------------------------------------------
> To unsubscribe, e-mail:
> For additional commands, e-mail:

To unsubscribe, e-mail:
For additional commands, e-mail: