In terms of security I try to extend the communication between my client and my API with a session. The client sends its header to the API and the API generates a session.
Client:
public static JSONObject send(String info)
{
StringBuffer resp = new StringBuffer();
try
{
URL url = new URL( "http://localhost:8080/myapi/" );
HttpURLConnection con = ( HttpURLConnection ) url.openConnection() );
con.setRequestMethod("POST");
con.setRequestProperty( "USER-AGENT", USER_AGENT );
con.setRequestProperty( "Accept-Charset", "UTF-8");
con.setRequestProperty( "Content-Type", "application/json" );
con.setDoOutput( true );
String data = info ;
DataOutputStream output = new DataOutputStream( con.getOutputStream);
output.writeBytes( data );
output.flush();
output.close();
int returnCode = con.getResponseCode();
BufferedReader reader = null;
if (returnCode==200)
{
reader = new BufferedReader( new InputStreamReader(con.getInputStream()));
}
else
{
reader = new BufferedReader( new InputStreamReader(con.getErrorStream()));
}
String input;
while( ( input = reader.readLine() ) != null )
{
resp.append( input );
}
reader.close();
return new JSONObject( resp.toString() );
}
catch( Exception e )
{
System.out.println( e.getMessage() );
return new JSONObject( resp.toString() );
}
finally
{
if( con != null )
{
con.disconnect();
}
}
}
API:
HttpServletRequest request = requestGlobals.getHttpServletRequest();
HttpSession session = request.getSession();
Idea: The first request with send creates the connection with the API and the API generates the session which is stored inside it. The second send from the same client should send the same header, so the API can generate the same session and compared it to the saved one. For example, I am able to guarantee further calls only after a successful login
Problem: If the connection is reestablished on the second send, the same client sends a different header with a different content length, resulting in a different session being generated. I tried to set a if( con == null ) around the area where the connection is build at the client but that didn't solve my problem.
Question: What do i have to do so that the second send uses the already existing connection or send the same header?