Skip to content

Commit ab478a1

Browse files
abramofranchettijzheaux
authored andcommitted
Clarify Effects Disabling CSRF Has On Logout
Issue gh-13062
1 parent cc86afe commit ab478a1

File tree

1 file changed

+2
-0
lines changed
  • docs/modules/ROOT/pages/servlet/authentication

1 file changed

+2
-0
lines changed

docs/modules/ROOT/pages/servlet/authentication/logout.adoc

+2
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,8 @@ When you include {spring-boot-reference-url}using.html#using.build-systems.start
2424
If you request `GET /logout`, then Spring Security displays a logout confirmation page.
2525
Aside from providing a valuable double-checking mechanism for the user, it also provides a simple way to provide xref:servlet/exploits/csrf.adoc[the needed CSRF token] to `POST /logout`.
2626

27+
Please note that if xref:servlet/exploits/csrf.adoc[CSRF protection] is disabled in configuration, no logout confirmation page is shown to the user and the logout is performed directly.
28+
2729
[TIP]
2830
In your application it is not necessary to use `GET /logout` to perform a logout.
2931
So long as xref:servlet/exploits/csrf.adoc[the needed CSRF token] is present in the request, your application can simply `POST /logout` to induce a logout.

0 commit comments

Comments
 (0)