• 在项目启动类中重写SpringBootServletInitializer类中的 up方法
  • 亲自测试过在配置文件中配置server.servlet.session.tracking-modes=和server.servlet.session.cookie.http-only=不起效果
  • Whether to use "HttpOnly" cookies for session cookies
  • Session tracking modes
@Override    public void  up(ServletContext servletContext) throws ServletException {        super. up(servletContext);        servletContext.setSessionTrackingModes(Collections.singleton(SessionTrackingMode.COOKIE));        SessionCookieConfig sessionCookieConfig = servletContext.getSessionCookieConfig();        sessionCookieConfig.setHttpOnly(true);    }
收藏 打印