[Resin-interest] question about secure / non -secure sessions

2007-01-11 Thread James Picklesimer
I have a developer who uses HTTP on a landing page then switches to HTTPS (SSL) with a small amount of data from the non-secure page. My opinion is this is a bad practice for security, but frying that fish is not for this forum. 1) does resin 3.0.18 or for that matter any J2EE container allow

Re: [Resin-interest] question about secure / non -secure sessions

2007-01-11 Thread James Picklesimer
Thanks for the clarification Scott. +James P. --- Scott Ferguson [EMAIL PROTECTED] wrote: On Jan 11, 2007, at 12:40 PM, James Picklesimer wrote: I have a developer who uses HTTP on a landing page then switches to HTTPS (SSL) with a small amount of data from the non-secure page.