浏览代码

SEC-359: Logout even if not logged in.

Ben Alex 19 年之前
父节点
当前提交
5911234f65
共有 1 个文件被更改,包括 2 次插入4 次删除
  1. 2 4
      core/src/main/java/org/acegisecurity/ui/logout/LogoutFilter.java

+ 2 - 4
core/src/main/java/org/acegisecurity/ui/logout/LogoutFilter.java

@@ -94,10 +94,8 @@ public class LogoutFilter implements Filter {
                 logger.debug("Logging out user '" + auth + "' and redirecting to logout page");
             }
 
-            if (auth != null) {
-                for (int i = 0; i < handlers.length; i++) {
-                    handlers[i].logout(httpRequest, httpResponse, auth);
-                }
+            for (int i = 0; i < handlers.length; i++) {
+                handlers[i].logout(httpRequest, httpResponse, auth);
             }
 
             sendRedirect(httpRequest, httpResponse, logoutSuccessUrl);