November 2017
Intermediate to advanced
542 pages
14h 24m
English
SessionFixationProtectionStrategy removed the setRetainedAttributes method in favor of users subclassing SessionFixationProtectionStrategy and overriding the extractAttributes method. Look at the following code:
SessionFixationProtectionStrategy strategy = new SessionFixationProtectionStrategy();strategy.setRetainedAttributes(attrsToRetain);
It should be replaced with:
public class AttrsSessionFixationProtectionStrategy extends SessionFixationProtectionStrategy { private final Collection<String> attrsToRetain; public AttrsSessionFixationProtectionStrategy( Collection<String> attrsToRetain) { this.attrsToRetain = attrsToRetain; } @Override protected Map<String, Object> extractAttributes(HttpSession session) ...Read now
Unlock full access