Typical usage includes session-fixation protection attack prevention, detection of session timeouts and restrictions on how many sessions an authenticated user may have open concurrently., so if you are using a customized form-login class, for example, you will need to inject it into both of these.