SEC-1424: Add new option create-session="stateless" #1667

Closed
spring-issuemaster opened this Issue Feb 26, 2010 · 1 comment

Projects

None yet

1 participant

@spring-issuemaster

Luke Taylor (Migrated from SEC-1424) said:

create-session="stateless" would mean that the application guarantees that no session will be created. In this case, we should be able to use a null RequestCache in the ExceptionTranslationFilter and remove the RequestCacheFilter and SessionManagementFilter from the stack.

This differs from the existing create-session="never" which means that Spring Security will not create a session, but will use an existing one if the application creates it.

@spring-issuemaster

Luke Taylor said:

Done. In addition to the above changes, a NullSecurityContextRepository will be used with the SecurityContextPersistenceFilter.

@spring-issuemaster spring-issuemaster added this to the 3.1.0.M1 milestone Feb 5, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment