Package org.forgerock.http.session
Interface Session
An interface for managing attributes across multiple requests from the same user agent.
Implementations should expose underlying container session attributes through this
interface if applicable.
New keys added to a session object should be named in a manner that avoids possible collision with keys added by other objects in the heap.
-
Nested Class Summary
-
Method Summary
Modifier and TypeMethodDescriptiondefault voidRenews the session identifier: the session content is transferred to a new session, referenced by a new server-generated, cryptographically strong identifier.Methods inherited from interface java.util.Map
clear, compute, computeIfAbsent, computeIfPresent, containsKey, containsValue, entrySet, equals, forEach, get, getOrDefault, hashCode, isEmpty, keySet, merge, put, putAll, putIfAbsent, remove, remove, replace, replace, replaceAll, size, values
-
Method Details
-
renewSessionId
default void renewSessionId()Renews the session identifier: the session content is transferred to a new session, referenced by a new server-generated, cryptographically strong identifier. The old session identifier must not be referenced anymore: a client presenting it after this call must not be able to reach this session's content through it.This is the primitive required to protect against session fixation attacks: the identifier under which authenticated state will be stored must never have been known to (or minted by) a third party before the authentication took place.
The default implementation does nothing: only session implementations that actually manage a session identifier can renew it. Stateless session implementations (where the content travels with the client, e.g. JWT-based sessions) have no server-side identifier to renew, and renewing their content is not achievable through this API.
-