# Set this to true to invalidate the session when a user logs into the # portal. This helps prevent phishing. Set this to false if you need the # guest user and the authenticated user to have the same session. # # Set this to false if the property "company.security.auth.requires.https" # is set to true and you want to maintain the same credentials across HTTP # and HTTPS sessions. # session.enable.phishing.protection=true