The following issue is raised by Jan Bartel <firstname.lastname@example.org>.
See email discussion in email@example.com .
In p.141 of 13.10 "Login and Logout" of Servlet 3.0 spec, it has:
"If a developer creates a session while a user is not authenticated, and the container then authenticates the user, the session visible to developer code after login must be the same session object that was created prior to login occurring so that there is no loss of session information."
The session content rather than the session object must be kept.
So, it is a bug in the spec.