Skip to content

Commit 6fb3719

Browse files
committedAug 21, 2017
AMBARI-21675.Add Secure Flag to Cookie / JSESSIONID in Zeppelin(Prabhjyot Singh via Venkata Sairam)
1 parent 705a62b commit 6fb3719

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed
 

‎ambari-server/src/main/resources/common-services/ZEPPELIN/0.6.0.2.5/configuration/zeppelin-shiro-ini.xml

+6
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,12 @@ sessionManager = org.apache.shiro.web.session.mgt.DefaultWebSessionManager
6161
cacheManager = org.apache.shiro.cache.MemoryConstrainedCacheManager
6262
securityManager.cacheManager = $cacheManager
6363

64+
cookie = org.apache.shiro.web.servlet.SimpleCookie
65+
cookie.name = JSESSIONID
66+
cookie.secure = true
67+
cookie.httpOnly = true
68+
sessionManager.sessionIdCookie = $cookie
69+
6470
securityManager.sessionManager = $sessionManager
6571
# 86,400,000 milliseconds = 24 hour
6672
securityManager.sessionManager.globalSessionTimeout = 86400000

0 commit comments

Comments
 (0)