The 1st request is handled by a servlet where 4 cookies are set and then request is forwarded to a JSP.
The JSP's response header when studied using Development tool's Network tab can be seen to have all the cookies in the response header.
The JSP form's action is a servlet. This is where my question is.
The request received in the 2nd servlet when queried appears to NOT contain any Secure Cookies and the HTTPOnly cookies also do not
show up as HTTPOnly(ck.isHttpOnly()). WHY is this so?
No matter. Try again. Fail again. Fail better. This time, do it with this tiny ad:
SKIP - a book about connecting industrious people with elderly land owners