SLING-1762 Add the HttpOnly attribute to setting the authentication cookie to make sure the cookie is not available to client side JavaScript. Also, when extracting the authentication data from the cookie ignore empty values.

git-svn-id: https://svn.apache.org/repos/asf/sling/trunk@996543 13f79535-47bb-0310-9956-ffa450edef68
1 file changed
tree: 0d204e0113d51fc4fa15553e26863c1934a8e1a7
  1. src/
  2. pom.xml
  3. README.txt