jesse-gallagher / frostillic.us-Blog

http://frostillic.us
Apache License 2.0
8 stars 0 forks source link

Remove JSESSIONID for non-authenticated requests if possible #48

Closed jesse-gallagher closed 5 years ago

jesse-gallagher commented 5 years ago

The only way it's used in the app is for logged-in users - ideally, it wouldn't send any cookies at all for anonymous users.

jesse-gallagher commented 5 years ago

It looks like there are at least two culprits that end up spawning a Servlet session currently: