I don't think BASIC authentication involves the session at all. This would mean that invalidating the session would have no effect on it.

It looks like sending a 401 status ("Unauthorized") will cause most browsers to clear their authentication cache, effectively asking the user for a new challenge again. You could try that.

-Erik

Eric van der Vlist wrote:
Hi,


When I change the authentication method from "FORM" to "BASIC", the authentication itself still works nicely, but I can't logout any longer...

Is oxf:session-invalidator supposed to work with BASIC authentication?

Thanks,

Eric (still running 2.7.2)


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl
_______________________________________________
orbeon-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/orbeon-user

Reply via email to