Visitor Session State Management
Info: This feature in Bloomreach Content requires a standard or premium license. Contact Bloomreach for licensing details.
Overview
Bloomreach Commerce Accelerator tracks visitor session states, including authentication status and cart data. By default, these session states are stored in the HttpSession. You can also configure the application to store session states in cookies.
Default Behavior: Storing in HttpSession
By default, the following session states are stored in the HttpSession for each visitor:
- The
Cartobject, which contains the visitor's current cart data. - The
StoreUserobject, which contains the visitor's authentication status.
Both session states share the lifecycle of the visitor's HttpSession. The session expires if the visitor is inactive for longer than the maximum inactive interval, as defined by HttpSession#getMaxInactiveInterval().
Alternative Behavior: Storing in Cookies
You can configure the application to store either session state in cookies instead of the HttpSession.
Storing session state in cookies is less secure than using the default HttpSession. Evaluate your security requirements before enabling these options. All cookies used for session state are marked as HttpOnly to reduce security risks.
Store Cart Data in a Cookie
To store the visitor's cart data in a cookie, set the following property to false in your HST-2 Container configuration file (for example, conf/hst.properties):
# Flag whether the visitor's store user info is stored in httpSession or cookie. true by default.
starterstore.cart.info.management.httpSessionBased = false
# The max age in seconds of the cookie for the visitor's cart info (e.g, cartId). 604800 seconds == 7 days by default.
starterstore.cart.info.management.cookie.maxAgeSeconds = 604800
You can adjust the cookie's lifetime by setting the starterstore.cart.info.management.cookie.maxAgeSeconds property.
Store StoreUser Data in a Cookie
To store the StoreUser object in a cookie, set the following property to false in your HST-2 Container configuration file (for example, conf/hst.properties):
# Flag whether the visitor's cart info (e.g, cartId) is stored in httpSession or cookie. true by default.
starterstore.store.user.management.httpSessionBased = false
Info: When you store the
StoreUserdata in a cookie, the cookie is temporary and stored in the browser's memory until the browser is closed. TheStoreUsercookie also expires if the visitor is inactive for longer than the maximum session inactive interval, as defined byHttpSession#getMaxInactiveInterval().