You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring MVC跳转支付服务商返回时创建新会话问题求助

New HttpSession Created After Returning From Payment Provider in Spring MVC/WebFlow/Security App

I've built an application that integrates Spring MVC, Spring WebFlow, and Spring Security. When users are redirected to our payment service provider and then return to our system, a new HttpSession is being created. I've set up an HttpSessionListener to monitor session activity, and I can confirm the old session isn't deleted—but a fresh session is generated upon the user's return.

Key Request & Response Breakdown

  1. Before redirecting to payment provider:

    • My app sends a GET /my-web/registration/create/new?execution=e1s5 HTTP/1.1 request, carrying the existing session cookie JSESSIONID=tramjzpvaxingk1wg4cnard
    • The server responds with HTTP/1.1 200 OK
  2. On the payment provider's page:

    • A POST /payment HTTP/1.1 request is sent to payment-web-sogenactif.test.sips-atos.com
    • The payment provider returns HTTP/1.1 302 Found and sets a TS0170356f cookie
  3. After returning to our app from payment provider:

    • A POST /my-web/payment/paypage/manual/response/L2lyLXdlYi9yZWdpc3RyYXRpb24vY3JlYXRlL25ldz9leGVjdXRpb249ZTFzNQ==/YWI3ZGEyOTMtMzhjOC00YjgwLWJlNTYtZDAxYjc3OGQ4MTJl HTTP/1.1 request hits localhost:61611
    • Our server responds with HTTP/1.1 302 Found and sets a brand new JSESSIONID=12ev6ciac4on91rondlvyrlycq

Core Observation

In normal redirect flows, our app doesn't generate a new JSESSIONID—but this specific return path from the payment provider is triggering an unexpected session creation. I'm hoping to get help from fellow developers to figure out why this is happening and how to fix it.

内容的提问来源于stack exchange,提问作者SME

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 07:44:21