Resolution: Works as designed
Affects Version/s: None
Fix Version/s: None
The following issue is raised by Jan Bartel <email@example.com>.
See email discussion in firstname.lastname@example.org .
In p.141 of 13.10 "Login and Logout" of Servlet 3.0 spec, it has:
"If a developer creates a session while a user is not authenticated, and the container then authenticates the user, the session visible to developer code after login must be the same session object that was created prior to login occurring so that there is no loss of session information."
The session content rather than the session object must be kept.
So, it is a bug in the spec.
|Field||Original Value||New Value|
|Summary||Should keep session context rather than session object after programmatic login||Should keep session content rather than session object after programmatic login|
|Status||Open [ 1 ]||Closed [ 6 ]|
|Resolution||Works as designed [ 7 ]|