Class LogoutConfigurer
java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.LogoutConfigurer
Sign-out: POST /logout ends the session, forgets who was signed in and
redirects to /login?logout. A chain with formLogin has it without
asking; any other chain has it once it calls http.logout(...).
http.logout(logout -> logout
.logoutUrl("/signout")
.logoutSuccessUrl("/")
.deleteCookies("remember"));
The request must be a POST while CSRF protection is on, so that a link on another site cannot sign a user out; with it off, any method does.
-
Method Summary
Modifier and TypeMethodDescriptionaddLogoutHandler(LogoutHandler logoutHandler) Something more to undo at sign-out; runs before the session ends.clearAuthentication(boolean clearAuthentication) Whether signing out forgets who was signed in; true unless changed.voidconfigure(HttpSecurity http) Adds this part's filters; nothing by default.deleteCookies(String... cookieNamesToClear) Cookies to delete at sign-out, by name; each must have been set with the path/.voidinit(HttpSecurity http) Shares what other parts need to know; nothing by default.invalidateHttpSession(boolean invalidateHttpSession) Whether signing out ends the session; true unless changed.logoutRequestMatcher(RequestMatcher logoutRequestMatcher) The requests that sign out, in place of the path and its method rule.logoutSuccessHandler(LogoutSuccessHandler logoutSuccessHandler) Answers the sign-out itself, instead of the redirect.logoutSuccessUrl(String logoutSuccessUrl) Where a signed-out user goes.The path that signs out.Lets everyone reach the page a signed-out user is sent to.Methods inherited from class SecurityConfigurer
disable, getBuilder
-
Method Details
-
logoutUrl
The path that signs out. -
logoutRequestMatcher
The requests that sign out, in place of the path and its method rule. -
logoutSuccessUrl
Where a signed-out user goes. -
logoutSuccessHandler
Answers the sign-out itself, instead of the redirect. -
invalidateHttpSession
Whether signing out ends the session; true unless changed. -
clearAuthentication
Whether signing out forgets who was signed in; true unless changed. -
deleteCookies
Cookies to delete at sign-out, by name; each must have been set with the path/. -
addLogoutHandler
Something more to undo at sign-out; runs before the session ends. -
permitAll
Lets everyone reach the page a signed-out user is sent to. -
init
Description copied from class:SecurityConfigurerShares what other parts need to know; nothing by default.- Overrides:
initin classSecurityConfigurer
-
configure
Description copied from class:SecurityConfigurerAdds this part's filters; nothing by default.- Overrides:
configurein classSecurityConfigurer
-