main change is to force spring security to always send user to welcome.mvc after login which gets their session setup properly before redirecting to start.mvc
updated spring and spring security versions
git-svn-id: http://webgoat.googlecode.com/svn/branches/webgoat-6.0@485 4033779f-a91e-0410-96ef-6bf7bf53c507