Menu ▾ ▴

#19 sessions are too easily created

open
nobody
None
5
2005-03-31
2005-03-31
No

I have an app that tries to avoid creating a session
until it actually needs one. If I use sslext a session
is always created due to some code in
SecureRequestUtils.reclaimRequestAttributes().

(called from SecureRequestUtils.getRedirectString(),
from SecureRequestUtils.checkSsl() from
SecureTilesRequestProcessor.process().)

The fix is pretty easy: just check for an existing
session first.
A patch for
org/apache/struts/util/SecureRequestUtils.java is attached.

Discussion

  • Eric Haszlakiewicz

    Patch to fix spurious session creation.

     
  • Nobody/Anonymous

    Logged In: NO

    Sigh, I've been struck by this as well.

     

Log in to post a comment.