Re: Multiple JSESSIONID cookies being presented.

2015-09-11 Thread Christopher Schultz
ers@tomcat.apache.org> >> Subject: Re: Multiple JSESSIONID cookies being presented. >> >> -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 >> >> Jeffrey, >> >> On 9/10/15 12:26 PM, Jeffrey Janner wrote: >>> Thanks for all the help guys. I think I'v

RE: Multiple JSESSIONID cookies being presented.

2015-09-11 Thread Jeffrey Janner
> -Original Message- > From: Caldarale, Charles R [mailto:chuck.caldar...@unisys.com] > Sent: Thursday, September 10, 2015 12:01 PM > To: Tomcat Users List <users@tomcat.apache.org> > Subject: RE: Multiple JSESSIONID cookies being presented. > > > From: Jeff

RE: Multiple JSESSIONID cookies being presented.

2015-09-11 Thread Jeffrey Janner
> -Original Message- > From: Christopher Schultz [mailto:ch...@christopherschultz.net] > Sent: Thursday, September 10, 2015 2:24 PM > To: Tomcat Users List <users@tomcat.apache.org> > Subject: Re: Multiple JSESSIONID cookies being presented. > > -BEGIN PGP

RE: Multiple JSESSIONID cookies being presented.

2015-09-10 Thread Jeffrey Janner
> -Original Message- > From: Christopher Schultz [mailto:ch...@christopherschultz.net] > Sent: Wednesday, September 09, 2015 1:50 PM > To: Tomcat Users List <users@tomcat.apache.org> > Subject: Re: Multiple JSESSIONID cookies being presented. > > -BEGIN PGP

RE: Multiple JSESSIONID cookies being presented.

2015-09-10 Thread Caldarale, Charles R
> From: Jeffrey Janner [mailto:jeffrey.jan...@polydyne.com] > Subject: RE: Multiple JSESSIONID cookies being presented. > I checked the error.jsp file and it does have session=true set, and if the > icon file > is missing, the error.jsp is definitely being sent. >

Re: Multiple JSESSIONID cookies being presented.

2015-09-10 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Jeffrey, On 9/10/15 12:26 PM, Jeffrey Janner wrote: > Thanks for all the help guys. I think I've sussed out what is > going on here. Now just have to get the Dev guys to address it. > > After spending a good bit of time clearing and watching

RE: Multiple JSESSIONID cookies being presented.

2015-09-09 Thread Jeffrey Janner
> -Original Message- > From: Igor Cicimov [mailto:icici...@gmail.com] > Sent: Tuesday, September 08, 2015 10:09 PM > To: Tomcat Users List <users@tomcat.apache.org> > Subject: RE: Multiple JSESSIONID cookies being presented. > > On 09/09/2015 7:13 AM, &q

RE: Multiple JSESSIONID cookies being presented.

2015-09-09 Thread Jeffrey Janner
> -Original Message- > From: Caldarale, Charles R [mailto:chuck.caldar...@unisys.com] > Sent: Tuesday, September 08, 2015 4:58 PM > To: Tomcat Users List <users@tomcat.apache.org> > Subject: RE: Multiple JSESSIONID cookies being presented. > > > From: Jose

Re: Multiple JSESSIONID cookies being presented.

2015-09-09 Thread Christopher Schultz
ers@tomcat.apache.org> >> Subject: RE: Multiple JSESSIONID cookies being presented. >> >>> From: Jose María Zaragoza [mailto:demablo...@gmail.com] >>> Subject: Re: Multiple JSESSIONID cookies being presented. >> >>>> Thanks for the clarification of what

Re: Multiple JSESSIONID cookies being presented.

2015-09-09 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Jeffrey, On 9/4/15 4:40 PM, Jeffrey Janner wrote: > I'm surprised that Tomcat would use the "wrong" session id for > URL-rewriting when presenting the login screen. Are you saying > that, when showing the login page for /APP2, Tomcat will: > > a.

Re: Multiple JSESSIONID cookies being presented.

2015-09-09 Thread Jose María Zaragoza
che.org> >> Subject: RE: Multiple JSESSIONID cookies being presented. >> >> > From: Jose María Zaragoza [mailto:demablo...@gmail.com] >> > Subject: Re: Multiple JSESSIONID cookies being presented. >> >> > > Thanks for the clarification of what's supposed

RE: Multiple JSESSIONID cookies being presented.

2015-09-08 Thread Jeffrey Janner
> -Original Message- > From: Jose María Zaragoza [mailto:demablo...@gmail.com] > Sent: Tuesday, September 08, 2015 9:22 AM > To: Tomcat Users List <users@tomcat.apache.org> > Subject: Re: Multiple JSESSIONID cookies being presented. > > 2015-09-08 15:

RE: Multiple JSESSIONID cookies being presented.

2015-09-08 Thread Caldarale, Charles R
> From: Jose María Zaragoza [mailto:demablo...@gmail.com] > Subject: Re: Multiple JSESSIONID cookies being presented. > > Thanks for the clarification of what's supposed to happen on receipt, Jose. > > However, I am describing what happens on first contact from the client

RE: Multiple JSESSIONID cookies being presented.

2015-09-08 Thread Jeffrey Janner
> -Original Message- > From: Jose María Zaragoza [mailto:demablo...@gmail.com] > Sent: Tuesday, September 08, 2015 9:08 AM > To: Tomcat Users List <users@tomcat.apache.org> > Subject: Re: Multiple JSESSIONID cookies being presented. > > 2015-09-08 15:

Re: Multiple JSESSIONID cookies being presented.

2015-09-08 Thread Jose María Zaragoza
2015-09-08 22:57 GMT+02:00 Jeffrey Janner <jeffrey.jan...@polydyne.com>: >> -Original Message- >> From: Jose María Zaragoza [mailto:demablo...@gmail.com] >> Sent: Tuesday, September 08, 2015 9:08 AM >> To: Tomcat Users List <users@tomcat.apache.org>

RE: Multiple JSESSIONID cookies being presented.

2015-09-08 Thread Jeffrey Janner
> -Original Message- > From: Christopher Schultz [mailto:ch...@christopherschultz.net] > Sent: Friday, September 04, 2015 12:46 PM > To: Tomcat Users List <users@tomcat.apache.org> > Subject: Re: Multiple JSESSIONID cookies being presented. > > -BEGIN PGP

Re: Multiple JSESSIONID cookies being presented.

2015-09-08 Thread Jose María Zaragoza
2015-09-08 15:51 GMT+02:00 Jeffrey Janner <jeffrey.jan...@polydyne.com>: >> -Original Message- >> From: Christopher Schultz [mailto:ch...@christopherschultz.net] >> Sent: Friday, September 04, 2015 12:46 PM >> To: Tomcat Users List <users@tomcat.apa

Re: Multiple JSESSIONID cookies being presented.

2015-09-08 Thread Jose María Zaragoza
2015-09-08 15:51 GMT+02:00 Jeffrey Janner <jeffrey.jan...@polydyne.com>: >> -Original Message- >> From: Christopher Schultz [mailto:ch...@christopherschultz.net] >> Sent: Friday, September 04, 2015 12:46 PM >> To: Tomcat Users List <users@tomcat.apa

RE: Multiple JSESSIONID cookies being presented.

2015-09-08 Thread Igor Cicimov
stopherschultz.net] > > >> Sent: Friday, September 04, 2015 12:46 PM > > >> To: Tomcat Users List <users@tomcat.apache.org> > > >> Subject: Re: Multiple JSESSIONID cookies being presented. > > >> > > >> -BEGIN PGP SIGNED MESSAGE-

RE: Multiple JSESSIONID cookies being presented.

2015-09-04 Thread Jeffrey Janner
> -Original Message- > From: Christopher Schultz [mailto:ch...@christopherschultz.net] > Sent: Friday, September 04, 2015 12:46 PM > To: Tomcat Users List <users@tomcat.apache.org> > Subject: Re: Multiple JSESSIONID cookies being presented. > > -BEGIN PGP

Re: Multiple JSESSIONID cookies being presented.

2015-09-04 Thread Christopher Schultz
ers@tomcat.apache.org> >> Subject: Re: Multiple JSESSIONID cookies being presented. >> > Jeffrey, > > On 9/4/15 12:37 PM, Jeffrey Janner wrote: >>>> I'm running Tomcat 8.0.24 on Ubuntu 14.04 with Java 8u45, but >>>> I'm also seeing this on Windows (versi

RE: Multiple JSESSIONID cookies being presented.

2015-09-04 Thread Jeffrey Janner
> -Original Message- > From: Christopher Schultz [mailto:ch...@christopherschultz.net] > Sent: Friday, September 04, 2015 2:55 PM > To: Tomcat Users List <users@tomcat.apache.org> > Subject: Re: Multiple JSESSIONID cookies being presented. > > -BEGIN PGP

Re: Multiple JSESSIONID cookies being presented.

2015-09-04 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Jeffrey, On 9/4/15 12:37 PM, Jeffrey Janner wrote: > I'm running Tomcat 8.0.24 on Ubuntu 14.04 with Java 8u45, but I'm > also seeing this on Windows (version doesn't matter), with Tomcat > 7.0.57 and Java 7u71, and Tomcat 6.0.43 and Java 7U51. >

Re: Multiple JSESSIONID

2013-03-02 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Jose, On 3/1/13 2:46 PM, Jose María Zaragoza wrote: I wonder why browsers don't send only one JSESSIONID If I request an URL as www.mydomain.com/app/myapplication/action.do and it has got 2 cookies with the same name, one for www.mydomain.com/

Re: Multiple JSESSIONID

2013-03-02 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Nick, On 3/1/13 2:58 PM, Nick Williams wrote: Browsers send all of the cookies because that's the compliant thing to do. RFC-2109 [1] says: If multiple cookies satisfy the criteria above, they are ordered in the Cookie header such that those

Re: Multiple JSESSIONID

2013-03-02 Thread Jose María Zaragoza
The moral of the story is that nested URL spaces is a bad idea where sessions are concerned. We easily fixed that problem by moving the /-mounted webapp to a unique URL prefix (which wasn't trivial, since we had inter-webapp links, etc.) but it solved all of those weird problems. Thanks. But

Re: Multiple JSESSIONID

2013-03-02 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Jose, On 3/2/13 2:25 PM, Jose María Zaragoza wrote: The moral of the story is that nested URL spaces is a bad idea where sessions are concerned. We easily fixed that problem by moving the /-mounted webapp to a unique URL prefix (which wasn't

Re: Multiple JSESSIONID

2013-03-01 Thread Jose María Zaragoza
and regards 2013/2/28 Caldarale, Charles R chuck.caldar...@unisys.com: From: Nick Williams [mailto:nicho...@nicholaswilliams.net] Subject: Re: Multiple JSESSIONID That's interesting. I would recommend a servlet filter that captures addCookie and friends to see where that extra one is being added

Re: Multiple JSESSIONID

2013-03-01 Thread Nick Williams
happen ? or is it created a new session with a new identifier ? Thanks and regards 2013/2/28 Caldarale, Charles R chuck.caldar...@unisys.com: From: Nick Williams [mailto:nicho...@nicholaswilliams.net] Subject: Re: Multiple JSESSIONID That's interesting. I would recommend a servlet filter

Re: Multiple JSESSIONID

2013-03-01 Thread Nick Williams
? Thanks and regards 2013/2/28 Caldarale, Charles R chuck.caldar...@unisys.com: From: Nick Williams [mailto:nicho...@nicholaswilliams.net] Subject: Re: Multiple JSESSIONID That's interesting. I would recommend a servlet filter that captures addCookie and friends to see where that extra one

Re: Multiple JSESSIONID

2013-03-01 Thread Jose María Zaragoza
2013/3/1 Nick Williams nicho...@nicholaswilliams.net: APOLOGIES FOR TOP POSTING! (see below, were I correctly inline post this apology) On Mar 1, 2013, at 1:58 PM, Nick Williams wrote: Browsers send all of the cookies because that's the compliant thing to do. RFC-2109 [1] says: If

Re: Multiple JSESSIONID

2013-03-01 Thread Ron McNulty
- Original Message - From: Jose María Zaragoza demablo...@gmail.com To: Tomcat Users List users@tomcat.apache.org Sent: Thursday, February 28, 2013 11:43 PM Subject: Multiple JSESSIONID Hello: We're using Tomcat 6.0.24 as servlet container This server listens for requests under

Re: Multiple JSESSIONID

2013-02-28 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Jose, On 2/28/13 2:43 AM, Jose María Zaragoza wrote: I've seen in my web browser that it has got 2 JSESSIONID for the same domain at the same time JSESSIONID: x www.mydomain.com / and JSESSIONID:

Re: Multiple JSESSIONID

2013-02-28 Thread Nick Williams
On Feb 28, 2013, at 10:50 AM, Christopher Schultz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Jose, On 2/28/13 2:43 AM, Jose María Zaragoza wrote: I've seen in my web browser that it has got 2 JSESSIONID for the same domain at the same time JSESSIONID: x

RE: Multiple JSESSIONID

2013-02-28 Thread Caldarale, Charles R
From: Nick Williams [mailto:nicho...@nicholaswilliams.net] Subject: Re: Multiple JSESSIONID That's interesting. I would recommend a servlet filter that captures addCookie and friends to see where that extra one is being added. The two JSESSIONIDs immediately above are in the request, so