Session Handling and Internet Explorer

    Jason Price


    I’d thought I’d ask here as I can’t find anything on the net (I’m probably not seraching for the right keywords).
    I have Jboss 4.0.0 and several webapps using struts 1.1 (all developed using myeclipseide).

    Everything works fine apart from IE 5+ default settings, basically the privacy options are stopping jboss from setting the session cookie unlees we change them.
    This is not a problem at the moment as we are using this on our intranet where we can control browser settings.
    However, we were planning to use jboss for our website where this would obviously be an issue.

    Does anyone know of a way around this other than setting browser settings?

    Riyad Kalla

    IE blocking cookies? I just don’t believe it… IE doesn’t block anything 😀

    I honestly have no idea why this wouldn’t be working, have you tried asking the JBoss list? I’m wondering if this is a red herring, are you sure of the problem? How high do your security defaults for IE default to? I believe only “HIGH” and above will block cookies, and the default out of the box pre-sp2 behavior is “MEDIUM”… even after SP2 I believe IE still allows cookies left and right… atleast I always have tons of tracker cookies when Adaware runs…

    Jason Price

    Thanks for the reply you reminded me of this problem. Its all to do with P3P and compact policies (if you’re having the same problem google about for compact poilcies and p3p and you’ll find lots of info). You have to have a compact privacy header in your responses from the website in order for the session cookies to be accpeted in IE.

    Riyad Kalla

    Funky we just shot outside the scope of “what I know about the internet” so I’m going to gracefully bow out of this topic now 😉

