Переглянути джерело

SEC-359: Logout even if not logged in.

Ben Alex 19 роки тому
батько
коміт
5911234f65

+ 2 - 4
core/src/main/java/org/acegisecurity/ui/logout/LogoutFilter.java

@@ -94,10 +94,8 @@ public class LogoutFilter implements Filter {
                 logger.debug("Logging out user '" + auth + "' and redirecting to logout page");
             }
 
-            if (auth != null) {
-                for (int i = 0; i < handlers.length; i++) {
-                    handlers[i].logout(httpRequest, httpResponse, auth);
-                }
+            for (int i = 0; i < handlers.length; i++) {
+                handlers[i].logout(httpRequest, httpResponse, auth);
             }
 
             sendRedirect(httpRequest, httpResponse, logoutSuccessUrl);