Thanks, but it should remove because of the refresh and that they are no longer logged in. If they were logged in the top image would show the username and a logout link. like
<http://shiro-user.582556.n2.nabble.com/file/n7578869/Screen_Shot_2013-06-21_at_5.05.10_PM.png> And on the server side there is the exception with now this sessionID (this is a day later so the image in my OP was a different login. <http://shiro-user.582556.n2.nabble.com/file/n7578869/Screen_Shot_2013-06-21_at_5.06.52_PM.png> Thanks for you help Mark -- View this message in context: http://shiro-user.582556.n2.nabble.com/Restarting-Tomcat-user-no-longer-logged-in-but-there-is-still-the-JSESSIONID-cookie-tp7578858p7578869.html Sent from the Shiro User mailing list archive at Nabble.com.
