sessions are too easily created
Brought to you by:
ditling
I have an app that tries to avoid creating a session
until it actually needs one. If I use sslext a session
is always created due to some code in
SecureRequestUtils.reclaimRequestAttributes().
(called from SecureRequestUtils.getRedirectString(),
from SecureRequestUtils.checkSsl() from
SecureTilesRequestProcessor.process().)
The fix is pretty easy: just check for an existing
session first.
A patch for
org/apache/struts/util/SecureRequestUtils.java is attached.
Patch to fix spurious session creation.
Logged In: NO
Sigh, I've been struck by this as well.