I don't get it. A minute ago you were proposing:

>The required change is fairly simple. Make the wicket session
>attribute name unique per servlet. Instead of "session", it should be
>"session" + request.getServletPath()

        Maybe I misundersood. Are we still going to be using jsessionid
as the cookie name but internally we use something different? I was
only talking about the external cookie name...

Gili

On Sat, 29 Jan 2005 19:43:03 +0100, Juergen Donnerstag wrote:

>On Sat, 29 Jan 2005 13:36:18 -0500, Gili <[EMAIL PROTECTED]> wrote:
>> 
>>         To my knowledge, all Servlet containers use "jsession" and they
>> assign it a random/unique value hence when you move across to different
>> webapps, they see an invalid/dead jsession ID and they realize that you
>> crossed webapps or you're trying to hack them and they reset your
>> cookie and give you a new jsession value. Why can't we do that?
>> 
>Yess JSESSIONID is defined in the spec.
>
>That is exactly what we (the servlet container) are doing. Please read
>my notes again and watch for the difference on web application (e.g.
>(/wicket-examples) and servlet (e.g. /wicket-examples/helloworld)
>
>Juergen
>
>
>-------------------------------------------------------
>This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
>Tool for open source databases. Create drag-&-drop reports. Save time
>by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
>Download a FREE copy at http://www.intelliview.com/go/osdn_nl
>_______________________________________________
>Wicket-develop mailing list
>[email protected]
>https://lists.sourceforge.net/lists/listinfo/wicket-develop
>




-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl
_______________________________________________
Wicket-develop mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/wicket-develop

Reply via email to