How to set cookie expiry time in pax-web ?
Issue
- Let us know whether it is possible to apply below in JBOSS FUSE configuration ? Cookie must be configured as follows:
- Setting Secure and HttpOnly attributes
- Setting a cookie expiry period
- Special characters (i.e. @,#,$) must be filtered out
Session Management must follow secure techniques (e.g. set a cookie expiry period, one-time cookie, HTTPS) to mitigate the risk of session hijacking and replay attacks.
Session id must be changed on login or upon re-authentication to prevent session fixation.
Environment
- Red Hat JBoss Fuse
- 6.x
- PAX-WEB
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.