How to preventing session fixation attacks with Spring Security? I am login in my system using spring security so that will generate session for logged user. Now if I stop my to