问题 I have a J2EE REST-based app using Spring Security 4.0.1.RELEASE. Needless to say, Spring documentation on sessionCreationPolicy and sessionFixation is sparse, aside from targeted questions here on StackOverflow. I'm using a Java-based config for Spring Security like this: @Configuration @EnableWebSecurity @EnableGlobalMethodSecurity(secureEnabled=true, prePostEnabled=true, jsr250Enabled=true, order=1) public class DefaultSecurityBeansConfig extends WebSecurityConfigurerAdapter { @Override