A pretty simple requirement. After logging into web J2EE 6 application, how can I have the user logout again?
Most (all?) the books and tutorials I have seen show h
You should have logout servlet/jsp which invalidates the session using the following ways:
session.invalidate() method which invalidates the session also. HttpServletRequest.logout() which invalidates only the security context and the session still exists.And, the Application UI should be providing a link which invokes that logout servlet/jsp
Question: Indeed, how can I force a logout after, say, the session times out, etc?
Answer: The in web.xml lets you define the timeout value after which the session will get invalidated by the server.