after upgrading from 0.9.0 to 1.0.0-RC2, i noticed that AnonymousProcessingFilter has begun creating sessions, specifically when it constructs a WebAuthenticationDetails.
i'm using anonymous authen for a simple REST-based protocol and don't ever want sessions to be created, so i've subclassed AnonymousProcessingFilter and overridded createAuthentication to use the two-argument constructor for WebAuthenticationDetails with the second set to 'false'. it would be preferable, i think, if AnonymousProcessingFilter had a parameter that controlled whether or not sessions can be created. thoughts? ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://sel.as-us.falkag.net/sel?cmd=lnk&kid3432&bid#0486&dat1642 _______________________________________________ Home: http://acegisecurity.org Acegisecurity-developer mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/acegisecurity-developer
