Add HttpOnly support to session cookies. It is enabled by default and can be disabled...
authormarkt <markt@13f79535-47bb-0310-9956-ffa450edef68>
Sat, 13 Sep 2008 17:39:47 +0000 (17:39 +0000)
committermarkt <markt@13f79535-47bb-0310-9956-ffa450edef68>
Sat, 13 Sep 2008 17:39:47 +0000 (17:39 +0000)
commitcf21c6cd897f87710f1540a6ba9b7923c340a073
tree0b76230cc20960c2c68a105ff050b70616899676
parentc4f622e137327d319f73db7f9407fa7dbbf051d0
Add HttpOnly support to session cookies. It is enabled by default and can be disabled at via manager configuration.
Based on a patch by Jim Manico.

git-svn-id: https://svn.apache.org/repos/asf/tomcat/trunk@694992 13f79535-47bb-0310-9956-ffa450edef68
java/org/apache/catalina/Manager.java
java/org/apache/catalina/connector/Request.java
java/org/apache/catalina/connector/Response.java
java/org/apache/catalina/session/ManagerBase.java
java/org/apache/tomcat/util/http/ServerCookie.java
webapps/docs/config/manager.xml