I have a SignOut button on my jsp page. (Tomcat 8.0.15)
session.invalidate()
or
request.logout()
which one is better for signing-out/terminating the session, what is the main difference? Should I use both?
I have a SignOut button on my jsp page. (Tomcat 8.0.15)
session.invalidate()
or
request.logout()
which one is better for signing-out/terminating the session, what is the main difference? Should I use both?
logout()
clears the identity information in the request but doesn't affect the sessioninvalidate()
invalidates the session but doesn't affect the identity information in the request.I think you should use both.