how do we make our JSESSIONID-Cookie HttpOnly?We know that App Engine runs on Servlet 2.5 which doesn't support this flag, but there must be a way around this.
Well, this can't be! How are others solving this?
I don't believe there's a way to do that.
If you want a workaround, you could try hosting a HTTPS version of your site on one subdomain, and the regular HTTP version on another subdomain. Mark the cookie as only available on a single subdomain.
--
You received this message because you are subscribed to the Google Groups "Google App Engine" group.
To unsubscribe from this group and stop receiving emails from it, send an email to google-appengi...@googlegroups.com.
To post to this group, send email to google-a...@googlegroups.com.
Visit this group at http://groups.google.com/group/google-appengine.
For more options, visit https://groups.google.com/d/optout.