Search code examples
jspsessiontomcatlogoutinvalidation

JSP session.invalidate() vs request.logout()


I have a SignOut button on my jsp page. (Tomcat 8.0.15)

session.invalidate()

or

request.logout()

which one is better for signing-out/terminating the session, what is the main difference? Should I use both?


Solution

    • logout() clears the identity information in the request but doesn't affect the session
    • invalidate() invalidates the session but doesn't affect the identity information in the request.

    I think you should use both.