I am building a RESTful web API in Spring Boot with my own implementation of JWT Authentication and my own authorization as well (not Spring Security). I simply wish to turn off JSESSIONID and run completely stateless, but the only documentation I can find is about turning off session only after enabling Spring Security (see here: How to make spring boot never issue session cookie? for example). I don't want Spring Security and I don't want HttpSession or JSESSIONID either.
Does setting server.session.timeout=0 in application.properties work? The doc does not specify the behavior if the timeout is set to 0.