Chenjp commented on PR #862: URL: https://github.com/apache/tomcat/pull/862#issuecomment-2937920885
> Thanks. Fixing this did not seem to be a bad idea, but the proposed patch seemed too convoluted. I did not add the test since encodeRedirectURL requires a real session (and it is already tested elsewhere). @rmaucher per servlet spec, When server support Session Tracking by COOKIE, and client browser does send cookie, it is not suitable to sends the encodeRedirectURL with path parameter jsessionid. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For queries about this service, please contact Infrastructure at: us...@infra.apache.org --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org