Visitor Session State Management

Info: This feature in Bloomreach Content requires a standard or premium license. Contact Bloomreach for licensing details.

Overview

Bloomreach Commerce Accelerator tracks visitor session states, including authentication status and cart data. By default, these session states are stored in the HttpSession. You can also configure the application to store session states in cookies.

Default Behavior: Storing in HttpSession

By default, the following session states are stored in the HttpSession for each visitor:

  • The Cart object, which contains the visitor's current cart data.
  • The StoreUser object, which contains the visitor's authentication status.

Both session states share the lifecycle of the visitor's HttpSession. The session expires if the visitor is inactive for longer than the maximum inactive interval, as defined by HttpSession#getMaxInactiveInterval().

Alternative Behavior: Storing in Cookies

You can configure the application to store either session state in cookies instead of the HttpSession.

Storing session state in cookies is less secure than using the default HttpSession. Evaluate your security requirements before enabling these options. All cookies used for session state are marked as HttpOnly to reduce security risks.

To store the visitor's cart data in a cookie, set the following property to false in your HST-2 Container configuration file (for example, conf/hst.properties):

# Flag whether the visitor's store user info is stored in httpSession or cookie. true by default.
starterstore.cart.info.management.httpSessionBased = false

# The max age in seconds of the cookie for the visitor's cart info (e.g, cartId). 604800 seconds == 7 days by default.
starterstore.cart.info.management.cookie.maxAgeSeconds = 604800

You can adjust the cookie's lifetime by setting the starterstore.cart.info.management.cookie.maxAgeSeconds property.

To store the StoreUser object in a cookie, set the following property to false in your HST-2 Container configuration file (for example, conf/hst.properties):

# Flag whether the visitor's cart info (e.g, cartId) is stored in httpSession or cookie. true by default.
starterstore.store.user.management.httpSessionBased = false

Info: When you store the StoreUser data in a cookie, the cookie is temporary and stored in the browser's memory until the browser is closed. The StoreUser cookie also expires if the visitor is inactive for longer than the maximum session inactive interval, as defined by HttpSession#getMaxInactiveInterval().

Share Feedback
Page: /frontend/commerce-accelerator/overview-setup/visitor-session-state-management
Section: Frontend
Category *
Visitor Session State Management | Bloomreach Content Documentation