How to make Requests HttpOnly in strus1.1 [on hold]
- by WSDL
I am using struts1.2 with jboss4 sever.I have to make my requests HttpOnly.How do I make this with jobss4 and struts1.2.Please Help me .It is urgent
private void validateToken(HttpServletRequest request, HttpServletResponse response) {
HttpSession session = request.getSession(true);
String token = (String)session.getAttribute(TOKEN_KEY);
if (token == null) {
token = getRandomString();
session.setAttribute(TOKEN_KEY, token);
// System.out.println("Executing the Filter............XSS1");
response.addHeader("Set-Cookie", "httpOnly");
}
}
private String getRandomString() {
return String.valueOf(System.currentTimeMillis());
}