1
0
mirror of synced 2026-08-06 02:08:01 +00:00

SEC-3032: Correct documented logout-success-url default

This commit is contained in:
Rob Winch
2015-07-22 13:48:07 -05:00
parent be27ede0e9
commit dab4cf18b8
3 changed files with 3 additions and 3 deletions
@@ -389,7 +389,7 @@ logout.attlist &=
## Specifies the URL that will cause a logout. Spring Security will initialize a filter that responds to this particular URL. Defaults to /logout if unspecified.
attribute logout-url {xsd:token}?
logout.attlist &=
## Specifies the URL to display once the user has logged out. If not specified, defaults to /.
## Specifies the URL to display once the user has logged out. If not specified, defaults to <form-login-login-page>/?logout (i.e. /login?logout).
attribute logout-success-url {xsd:token}?
logout.attlist &=
## Specifies whether a logout also causes HttpSession invalidation, which is generally desirable. If unspecified, defaults to true.
@@ -1355,7 +1355,7 @@
<xs:attribute name="logout-success-url" type="xs:token">
<xs:annotation>
<xs:documentation>Specifies the URL to display once the user has logged out. If not specified, defaults to
/.
&lt;form-login-login-page&gt;/?logout (i.e. /login?logout).
</xs:documentation>
</xs:annotation>
</xs:attribute>