Throw exception if session created after response

Closes gh-1798
This commit is contained in:
Eleftheria Stein
2021-03-25 09:27:27 +02:00
parent 15f29f8adf
commit 8bd4374909
2 changed files with 16 additions and 0 deletions

View File

@@ -310,6 +310,10 @@ public class SessionRepositoryFilter<S extends Session> extends OncePerRequestFi
if (!create) {
return null;
}
if (SessionRepositoryFilter.this.httpSessionIdResolver instanceof CookieHttpSessionIdResolver
&& this.response.isCommitted()) {
throw new IllegalArgumentException("Cannot create a session after the response has been committed");
}
if (SESSION_LOGGER.isDebugEnabled()) {
SESSION_LOGGER.debug(
"A new session was created. To help you troubleshoot where the session was created we provided a StackTrace (this is not an error). You can prevent this from appearing by disabling DEBUG logging for "