Interface Session

All Superinterfaces:
Map<String,Object>

public interface Session extends Map<String,Object>
An interface for managing attributes across multiple requests from the same user agent. Implementations should expose underlying container session attributes through this interface if applicable.

New keys added to a session object should be named in a manner that avoids possible collision with keys added by other objects in the heap.

  • Method Details

    • renewSessionId

      default void renewSessionId()
      Renews the session identifier: the session content is transferred to a new session, referenced by a new server-generated, cryptographically strong identifier. The old session identifier must not be referenced anymore: a client presenting it after this call must not be able to reach this session's content through it.

      This is the primitive required to protect against session fixation attacks: the identifier under which authenticated state will be stored must never have been known to (or minted by) a third party before the authentication took place.

      The default implementation does nothing: only session implementations that actually manage a session identifier can renew it. Stateless session implementations (where the content travels with the client, e.g. JWT-based sessions) have no server-side identifier to renew, and renewing their content is not achievable through this API.