SHIRO-361 Added property to support disabling of JSESSIONID in URL

This can be turned off by setting: `sessionManager.sessionIdUrlRewritingEnabled` to false (recommended)
in the shiro.ini (or equivalent configuration)

This is a stop gap on the way to SHIRO-360
5 files changed