See: Description
| Interface | Description | 
|---|---|
| SessionAuthenticationStrategy | Allows pluggable support for HttpSession-related behaviour when an authentication occurs. | 
| Class | Description | 
|---|---|
| ConcurrentSessionControlStrategy | Strategy which handles concurrent session-control, in addition to the functionality provided by the base class. | 
| NullAuthenticatedSessionStrategy | |
| SessionFixationProtectionStrategy | The default implementation of  SessionAuthenticationStrategy. | 
| Exception | Description | 
|---|---|
| SessionAuthenticationException | Thrown by an SessionAuthenticationStrategy to indicate that an authentication object is not valid for
 the current session, typically because the same user has exceeded the number of sessions they are allowed to have
 concurrently. | 
Comes with support for: