public final class ChangeSessionIdAuthenticationStrategy extends AbstractSessionFixationProtectionStrategy
HttpServletRequest.changeSessionId() to protect against session fixation
attacks. This is the default implementation.AbstractSessionFixationProtectionStrategy.NullEventPublisherlogger| Constructor and Description |
|---|
ChangeSessionIdAuthenticationStrategy() |
onAuthentication, onSessionChange, setAlwaysCreateSession, setApplicationEventPublisher