Title:
CFID & CFTOKEN include "hash" prefix this is not compatible with previous versions
| View in TrackerStatus/Resolution/Reason: Closed/Fixed/
Reporter/Name(from Bugbase): Mark Gaulin / Mark Gaulin (Mark Gaulin)
Created: 09/16/2015
Components: Core Runtime
Versions: 11.0
Failure Type: Data Loss
Found In Build/Fixed In Build: CF11_Final /
Priority/Frequency: Normal / Some users will encounter
Locale/System: ALL / Win 2008 Server
Vote Count: 1
Related Bugs:
CF-4107152 - Similar to
Problem Description: CF11 (and at least some recent updates to CF10) include some kind of "hash" prefix in front of the values of the CFID & CFTOKEN cookies. As far as I can tell, this change is not documented and cannot be disabled. This change breaks session sharing between servers running different of CF and it seems to break things when the host name and/or cfapplication name changes. (Our testing did not nail this down.)
I would have expected a change like this to be 1) documented and 2) able to be disabled via a jvm.config argument
Steps to Reproduce:
Hit a CF11 site that is not using "Use UUID for cftoken"
Actual Result:
CFID=Z4iqyj5ekgtiqnnaafjwnjfv918npvjndfx6r17xcvr0lrdc1ny-13223
Expected Result:
CFID=13223
Any Workarounds:
----------------------------- Additional Watson Details -----------------------------
Watson Bug ID: 4057613
External Customer Info:
External Company:
External Customer Name: Mark Gaulin
External Customer Email:
Attachments:
Comments: