getUserFromCookies(request, session); is a method iterates over the cookies in user's cache and try to create a session scope object. What do you think of my design ? is it good (implementation, performance, a hole ....) Thanks guys.
John, The logic/design are sound. My only question is why you are passing both request and session to the getUserFromCookies method. As you can get either from the other, this is a redundant parameter.
I would also move the chain doFilter() call outside the if statement since it is done either way. The intent is a bit clearer that way.