Hello. I found the following. http://example.com/SomeAction.action?session.somekey=someValue
This request rewrites the session. Does this become a security hole? Thanks. [EMAIL PROTECTED] --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]