Spring MVC跳转支付服务商返回时创建新会话问题求助
I've built an application that integrates Spring MVC, Spring WebFlow, and Spring Security. When users are redirected to our payment service provider and then return to our system, a new HttpSession is being created. I've set up an HttpSessionListener to monitor session activity, and I can confirm the old session isn't deleted—but a fresh session is generated upon the user's return.
Key Request & Response Breakdown
Before redirecting to payment provider:
- My app sends a
GET /my-web/registration/create/new?execution=e1s5 HTTP/1.1request, carrying the existing session cookieJSESSIONID=tramjzpvaxingk1wg4cnard - The server responds with
HTTP/1.1 200 OK
- My app sends a
On the payment provider's page:
- A
POST /payment HTTP/1.1request is sent topayment-web-sogenactif.test.sips-atos.com - The payment provider returns
HTTP/1.1 302 Foundand sets aTS0170356fcookie
- A
After returning to our app from payment provider:
- A
POST /my-web/payment/paypage/manual/response/L2lyLXdlYi9yZWdpc3RyYXRpb24vY3JlYXRlL25ldz9leGVjdXRpb249ZTFzNQ==/YWI3ZGEyOTMtMzhjOC00YjgwLWJlNTYtZDAxYjc3OGQ4MTJl HTTP/1.1request hitslocalhost:61611 - Our server responds with
HTTP/1.1 302 Foundand sets a brand newJSESSIONID=12ev6ciac4on91rondlvyrlycq
- A
Core Observation
In normal redirect flows, our app doesn't generate a new JSESSIONID—but this specific return path from the payment provider is triggering an unexpected session creation. I'm hoping to get help from fellow developers to figure out why this is happening and how to fix it.
内容的提问来源于stack exchange,提问作者SME

