Class LogoutConfigurer

java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.LogoutConfigurer

public final class LogoutConfigurer extends SecurityConfigurer

Sign-out: POST /logout ends the session, forgets who was signed in and redirects to /login?logout. A chain with formLogin has it without asking; any other chain has it once it calls http.logout(...).

http.logout(logout -> logout
        .logoutUrl("/signout")
        .logoutSuccessUrl("/")
        .deleteCookies("remember"));

The request must be a POST while CSRF protection is on, so that a link on another site cannot sign a user out; with it off, any method does.

  • Method Details

    • logoutUrl

      public LogoutConfigurer logoutUrl(String logoutUrl)
      The path that signs out.
    • logoutRequestMatcher

      public LogoutConfigurer logoutRequestMatcher(RequestMatcher logoutRequestMatcher)
      The requests that sign out, in place of the path and its method rule.
    • logoutSuccessUrl

      public LogoutConfigurer logoutSuccessUrl(String logoutSuccessUrl)
      Where a signed-out user goes.
    • logoutSuccessHandler

      public LogoutConfigurer logoutSuccessHandler(LogoutSuccessHandler logoutSuccessHandler)
      Answers the sign-out itself, instead of the redirect.
    • invalidateHttpSession

      public LogoutConfigurer invalidateHttpSession(boolean invalidateHttpSession)
      Whether signing out ends the session; true unless changed.
    • clearAuthentication

      public LogoutConfigurer clearAuthentication(boolean clearAuthentication)
      Whether signing out forgets who was signed in; true unless changed.
    • deleteCookies

      public LogoutConfigurer deleteCookies(String... cookieNamesToClear)
      Cookies to delete at sign-out, by name; each must have been set with the path /.
    • addLogoutHandler

      public LogoutConfigurer addLogoutHandler(LogoutHandler logoutHandler)
      Something more to undo at sign-out; runs before the session ends.
    • permitAll

      public LogoutConfigurer permitAll()
      Lets everyone reach the page a signed-out user is sent to.
    • init

      public void init(HttpSecurity http)
      Description copied from class: SecurityConfigurer
      Shares what other parts need to know; nothing by default.
      Overrides:
      init in class SecurityConfigurer
    • configure

      public void configure(HttpSecurity http)
      Description copied from class: SecurityConfigurer
      Adds this part's filters; nothing by default.
      Overrides:
      configure in class SecurityConfigurer