Index: lams_common/src/java/org/lamsfoundation/lams/integration/security/SsoHandler.java =================================================================== diff -u -rb2f5b5e883428dc03539ca5ed1ca323d1ab4e092 -r2ae1722c0ec29c4b29bc6fac2bc912e160e96f99 --- lams_common/src/java/org/lamsfoundation/lams/integration/security/SsoHandler.java (.../SsoHandler.java) (revision b2f5b5e883428dc03539ca5ed1ca323d1ab4e092) +++ lams_common/src/java/org/lamsfoundation/lams/integration/security/SsoHandler.java (.../SsoHandler.java) (revision 2ae1722c0ec29c4b29bc6fac2bc912e160e96f99) @@ -151,12 +151,6 @@ } - // prevent session fixation attack - // This will become obsolete on Undertow upgrade to version 1.1.10+ - SessionManager.removeSessionByID(session.getId(), false); - request.changeSessionId(); - session = request.getSession(); - // store session so UniversalLoginModule can access it SessionManager.startSession(request);