LDEV-4400 Disable session ID change on demand WildFly 10 changes session ID after log in by default. It prevent session fixation attack. Tes…
Show more
LDEV-4400 Disable session ID change on demandWildFly 10 changes session ID after log in by default. It preventsession fixation attack.TestHarness can not process it correctly. When calling /j_security_checkit gets session ID in SET-COOKIE header different to what Undertowgenerates. Browsers seem to have no problem with it, but TestHarnessfails to set correct session ID. That is why session ID change needs tobe disabled when running TH.
Show less