users@glassfish.java.net

Re: How to set JSESSIONID cookie secure even in HTTP in GF V2 UR2

From: <Jan.Luehe_at_Sun.COM>
Date: Tue, 10 Jun 2008 10:37:13 -0700

Hi 真嶌 晋,

>Hello,
>
>I know its possible by configuration file when GlassFish V2.1 is released.
>
>In my environment Apache is in front of GlassFish it path convert HTTPS to HTTP.
>I would like to set JSSESIONID cookie secure.
>
>Someone says on the net it's possible use HttpServletResponseWrapper#addCookie()
>It's not about GlassFish. If it's the solution that I want. I don't know detail.
>
>Does anyone give me the idea for that ?
>
>Is it impossible in GlassFish V2 UR2?
>
>

It's impossible with GlassFish V2 UR2, but will be possible with the
upcoming
GlassFish V2.1, by leveraging the cookie configuration in sun-web.xml.

See

https://glassfish.dev.java.net/issues/show_bug.cgi?id=3822

for details.

Let me know if you have any questions.

Thanks,


Jan

>Thanks,
>
>Susumu Majima
>
>
>---------------------------------------------------------------------
>To unsubscribe, e-mail: users-unsubscribe_at_glassfish.dev.java.net
>For additional commands, e-mail: users-help_at_glassfish.dev.java.net
>
>
>