- 在项目启动类中重写SpringBootServletInitializer类中的onStartup方法
- 亲自测试过在配置文件中配置server.servlet.session.tracking-modes=和server.servlet.session.cookie.http-only=不起效果
- Whether to use "HttpOnly" cookies for session cookies
- Session tracking modes
@Override
public void onStartup(ServletContext servletContext) throws ServletException {
super.onStartup(servletContext);
servletContext.setSessionTrackingModes(Collections.singleton(SessionTrackingMode.COOKIE));
SessionCookieConfig sessionCookieConfig = servletContext.getSessionCookieConfig();
sessionCookieConfig.setHttpOnly(true);
}