Friday 20 November 2015

What is the use case for overriding default login-processing-url in spring security


By default, the logout process will first invalidate the session, hence triggering the session management to redirect to the invalid session page. By specifying invalidate-session="false" will fix this behavior.
<sec:logout logout-success-url="/logout" invalidate-session="false" 
delete-cookies="JSESSIONID" />


No comments:

Post a Comment