public final class ChangeSessionIdAuthenticationStrategy extends AbstractSessionFixationProtectionStrategy
HttpServletRequest.changeSessionId()
to protect against session fixation
attacks. This is the default implementation.AbstractSessionFixationProtectionStrategy.NullEventPublisher
logger
Constructor and Description |
---|
ChangeSessionIdAuthenticationStrategy() |
onAuthentication, onSessionChange, setAlwaysCreateSession, setApplicationEventPublisher