Skip to content

Commit

Permalink
concord-server: invalidate session on failed login
Browse files Browse the repository at this point in the history
  • Loading branch information
ibodrov committed Jan 3, 2024
1 parent 72e7c2e commit 1b0415a
Showing 1 changed file with 6 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@
import javax.servlet.ServletResponse;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpSession;
import javax.ws.rs.core.HttpHeaders;
import javax.ws.rs.core.MediaType;
import java.io.IOException;
Expand Down Expand Up @@ -147,6 +148,11 @@ protected boolean onLoginFailure(AuthenticationToken token, AuthenticationExcept
s.logout();
}

HttpSession session = ((HttpServletRequest) request).getSession(false);
if (session != null) {
session.invalidate();
}

return super.onLoginFailure(token, e, request, response);
}

Expand Down

0 comments on commit 1b0415a

Please sign in to comment.