I added in my configuration the following property:


The Set-Cookie HTTP header is:

Set-Cookie: JSESSIONID=3407BD3E1C7153D70EFC5DBD16B059E4; Path=/; Secure; HttpOnly

So it seems like Spring ignores this property. Is it deprecated? If not, why isn't it working?

Here's my configuration:

protected void configure(HttpSecurity http) throws Exception {
            .defaultSuccessUrl("/", true)
            .logout().logoutRequestMatcher(new AntPathRequestMatcher("/logout"))

With Spring Boot 2.1.4 you have to use the property server.servlet.session.cookie.max-age instead of server.session.cookie.max-age, see Spring Boot Reference Guide:

server.servlet.session.cookie.max-age= # Maximum age of the session cookie. If a duration suffix is not specified, seconds will be used.

and Spring Boot 2.0.0 RC1 Configuration Changelog.