码迷,mamicode.com
首页 > Web开发 > 详细

关于tomcat7服务下面js无法获取JSESSIONID的cookie信息

时间:2016-01-13 21:33:20      阅读:998      评论:0      收藏:0      [点我收藏+]

标签:

http://tomcat.apache.org/tomcat-5.5-doc/config/context.html  

 

Does anyone know what changed in the configuration between Tomcat 6 and Tomcat 7 that would cause the JSESSIONID cookie to not be accessible via JavaScript?

Using Tomcat 6:

alert(document.cookie); // JSESSIONID=8675309ABCDEF...

Using Tomcat 7:

alert(document.cookie); // nothing



the answer as follow:

Okay, I found the answer. The useHttpOnly attribute was set to false by default in Tomcat 6, and is true in Tomcat 7. This attribute is set for the <Context> container.

<Context useHttpOnly="false" [...] />

For more information about updating from Tomcat 6 to 7: Migrating from 6.0.x to 7.0.x

I‘m not sure why I didn‘t see that in the docs before, but I‘ve verified that setting this to false does in fact cause Tomcat 7 to revert to the Tomcat 6 behavior.



关于tomcat7服务下面js无法获取JSESSIONID的cookie信息

标签:

原文地址:http://www.cnblogs.com/silentjesse/p/5128501.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!