spring-projects / spring-projects/spring-session

Extra session cookie randomly generated

Open
#3,312 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

status: waiting-for-triage type: bug
Dominant language
Java
Stars
1.9k
Forks
1.2k
Avg merge
4h 27m
Merged PRs (30d)
55

Description

We are using spring-web, spring session 3.4.1, tomcat. Sometimes an extra session cookie is getting generated randomly as follows

JSESSIONID	node0t2zjr9obxy80amzfh10llwlq50.node0	localhost	   /	Session	47 B		✓	

I could not find any resources related to the issue

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The report names spring-web, Spring Session 3.4.1, and Tomcat but no repository files, tests, or reproduction steps. Start by reproducing the extra JSESSIONID in that stack and tracing session-cookie handling; done would require a confirmed cause and a regression test showing only the intended cookie is generated.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
backend
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.