javasession-cookiesjboss5.x

Jboss 5. HttpOnly session cookies


How to configure JBoss 5.1.* to make session cookie HttpOnly?

<Context useHttpOnly="true">

Doesn't work.


Solution

  • Have you tried

    <SessionCookie secure="true" httpOnly="true" />
    

    as explained here.