hi all!
we´re using resin 3.0.23
is there a possibility to avoid session fixation?

it would be nice to have this both things:
- accept only session id´s generated by the application server
- change the session id after the login-procedure

-- 
GRATIS für alle GMX-Mitglieder: Die maxdome Movie-FLAT!
Jetzt freischalten unter http://portal.gmx.net/de/go/maxdome01


_______________________________________________
resin-interest mailing list
resin-interest@caucho.com
http://maillist.caucho.com/mailman/listinfo/resin-interest

Reply via email to