https introduce in acegi book

If session hijacking is considered too significant a risk for your particular application, the only option
is to use HTTPS for every request. This means the jsessionid is never sent across an insecure channel.
You will need to ensure your web.xml-defined <welcome-file> points to an HTTPS location, and the
application never directs the user to an HTTP location. Acegi Security provides a solution to assist
with the latter.
發佈了22 篇原創文章 · 獲贊 0 · 訪問量 1萬+
發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章