Trying to authenticate to a server which has custom session ID cookie name ("CO-JIRA-UAT-SESSIONID") and it fails on Rest HTTP connections because header and entity have different cookie IDs for the same cookie value
This is HTTP response header from Jira:
HTTP/1.1 200 OK [Server: Apache-Coyote/1.1,
X-AREQUESTID: 1105x1428x1,
X-ASEN: SEN-L12715432,
Set-Cookie: atlassian.xsrf.token=BLSF-LQ0P-MS29-IEDE|6d48bd80045fcf38da5cb17dbde8a85a268a0a2b|lout;
Path=/,
X-AUSERNAME: anonymous,
Set-Cookie: CO-JIRA-UAT-SESSIONID=FD362205300647206889432D669717C8;
Path=/;
HttpOnly,
X-Seraph-LoginReason: OK,
Cache-Control: no-cache,
no-store,
no-transform,
X-Content-Type-Options: nosniff,
Content-Type: application/json;charset=UTF-8,
Transfer-Encoding: chunked,
Date: Tue, 11 Dec 2018 17:25:00 GMT]
But this very response has also HttpEntity attached and it has JSESSIONID for same session ID:
{
"session":{"name":"JSESSIONID","value":"FD362205300647206889432D669717C8"},
"loginInfo":{"failedLoginCount":20,"loginCount":26998575,"lastFailedLoginTime":"2014-05-30T13:46:12.106+0200","previousLoginTime":"2018-12-11T18:20:48.096+0100"}
}
0-SESSIONID=FD362205300647206889432D669717C8;
Path=/;
HttpOnly
X-Seraph-LoginReason: OK
Cache-Control: no-cache, no-store, no-transform
X-Content-Type-Options: nosniff
Content-Type: application/json;
charset=UTF-8
Transfer-Encoding: chunked
Date: Tue, 11 Dec 2018 17:25:00 GMTAnd that messes authorization on my back-end because in the end the name from HttpEntity is taken and Jira expects session name as in header.
I suspect that "JSESSIONID" comes from Seraph (although I'm hitting back-end bypassing Apache SiteMinder and using basic authentication, not SSO). How can this cookie name also be changed?