I suggest using a network sniffer to see the HTTP headers during connections. Specifically, pay attention to the Set-Cookie header from the server and the Cookie header from the client. See if and when they are being sent, and if they match.
(J2O uses gzip compression, but that only affects the content part, not the header part)
__________________
With our extreme gelatinous apology,
We beg to inform your Imperial Majesty,
Unto whom be dominion and power and glory,
There still remains that strange precipitate
Which has the quality to resist
Our oldest and most trusted catalyst.
It is a substance we cannot cremate
By temperatures known to our Laboratory.
~ E.J. Pratt
|