(refs #1291)Add http-only attribute to JSESSIONID cookie

This commit is contained in:
Naoki Takezoe
2016-09-12 14:59:43 +09:00
parent 9e98d30612
commit db679967af

View File

@@ -88,6 +88,9 @@
<!-- ===================================================================== --> <!-- ===================================================================== -->
<session-config> <session-config>
<session-timeout>1440</session-timeout> <session-timeout>1440</session-timeout>
<cookie-config>
<http-only>true</http-only>
</cookie-config>
</session-config> </session-config>
<!-- ===================================================================== --> <!-- ===================================================================== -->