Spring Security
  1. Spring Security
  2. SEC-1379

New session should be created on invalid session detection

    Details

    • Type: Improvement Improvement
    • Status: Closed
    • Priority: Minor Minor
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 3.0.2
    • Component/s: Web
    • Labels:
      None

      Description

      At the moment, the user needs to both set up the session timeout page to bypass the filter chain and create a new session in the timeout page (to prevent the same invalid id being resubmitted). It would be simpler if the SessionManagementFilter just started a new session when the invalid session ID is detected.

        Activity

        There are no comments yet on this issue.

          People

          • Assignee:
            Luke Taylor
            Reporter:
            Luke Taylor
          • Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: