Add protection against session fixation attacks. Upon authentication, the
current session needs to be invalidated and a new session created, without
impacting the authenticated user.
Original issue reported on code.google.com by jrivard on 22 May 2013 at 6:23
Original issue reported on code.google.com by
jrivard
on 22 May 2013 at 6:23