https://bz.apache.org/bugzilla/show_bug.cgi?id=66471
--- Comment #2 from Reto Weiss <reto.we...@axonivy.com> --- The FilterChain could register the latest request in a ThreadLocal. Which is then read to use the isSecure flag from the most inner request when creating the session cookie. -- You are receiving this mail because: You are the assignee for the bug. --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org