jeudi 21 mai 2015

Session Management when part of an application is over http and some part on t https

I have an application (J2EE) which is partly on HTTP and partly on HTTPS. I want to have two session cookies to track a user, one when he on a HTTP page and other for HTTPS page.

I want the HTTPS cookie to secure and http-only. Is it possible?

Aucun commentaire:

Enregistrer un commentaire