Logout not clearing all cookies

classic Classic list List threaded Threaded
3 messages Options
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Logout not clearing all cookies

hipdragon
I was wondering if anyone had any advice on clearing out all the cookies during logout. I'm using Shiro logout filter and it only clears the session cookie. I was thinking i could override the logout filter, but it seems like this would be useful for everyone who uses Shiro web. In case it's helpful, I'm using JSF.

Hoping someone has figured this out and would be willing to share the solution.
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: Logout not clearing all cookies

Brian Demers
You could also create another filter (MyCustomCookieCleanUpFilter) and add configure that in addition to the current logout filter.  In that you could do any special clean up you needed.
You could even make it generic and supply a list of cookie names to remove.

-Brian

On Thu, Mar 9, 2017 at 1:09 PM, hipdragon <[hidden email]> wrote:
I was wondering if anyone had any advice on clearing out all the cookies
during logout. I'm using Shiro logout filter and it only clears the session
cookie. I was thinking i could override the logout filter, but it seems like
this would be useful for everyone who uses Shiro web. In case it's helpful,
I'm using JSF.

Hoping someone has figured this out and would be willing to share the
solution.



--
View this message in context: http://shiro-user.582556.n2.nabble.com/Logout-not-clearing-all-cookies-tp7581530.html
Sent from the Shiro User mailing list archive at Nabble.com.

Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: Logout not clearing all cookies

Rob Young
I was going to suggest the same.  WebServlet filters are amazing things.  :)


On Mar 10, 2017, at 1:14 PM, Brian Demers <[hidden email]> wrote:



On Thu, Mar 9, 2017 at 1:09 PM, hipdragon <[hidden email]> wrote:
I was wondering if anyone had any advice on clearing out all the cookies
during logout. I'm using Shiro logout filter and it only clears the session
cookie. I was thinking i could override the logout filter, but it seems like
this would be useful for everyone who uses Shiro web. In case it's helpful,
I'm using JSF.

Hoping someone has figured this out and would be willing to share the
solution.

Loading...