I'm having problems with form based authentication with the latest releases on tomcat4. Things work fine in 4.0-b1, but with the latest snapshots no cookie is being sent with the login page, and although authentication succeeds, redirection to the secured page fails with a 400 error returned. This behaviour can be produced in 4.0-b1 by refusing to accept the cookie. Is this a bug, or has something changed in how sessions/cookies are handled? Help appreciated. Thanks Tim -------------------------------------------------------- Dr.Tim Dudgeon <[EMAIL PROTECTED]> -------------------------------------------------- DISCLAIMER: This message contains proprietary information some or all of which may be confidential and/or legally privileged. It is for the intended recipient only who may use and apply the information only for the intended purpose. Internet communications are not secure and therefore the British Biotech group does not accept legal responsibility for the contents of this message. Any views or opinions presented are only those of the author and not those of the British Biotech group. If you are not the intended recipient please delete this e-mail and notify the author immediately by calling ++44 (0)1865 748747; do not use, disclose, distribute, copy, print or rely on this e-mail. --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, email: [EMAIL PROTECTED]