Hi Craig,

thanks for your fast reply. To avoid any misunderstandings - my tomcat
configuration works well (including sessions based on URL-rewriting) for my
(not that small) application, I just wanted to protect the admin-stuff.
I think your guess was right: Setting cookies to "true" solves this.
Switching back to URL-rewriting doesn't work.

If this is a bug, will it be fixed until the final release? (if not, I have
to deal with it...)

thanks,
pero

Reply via email to