This week's book giveaway is in the OO, Patterns, UML and Refactoring forum. We're giving away four copies of Refactoring for Software Design Smells: Managing Technical Debt and have Girish Suryanarayana, Ganesh Samarthyam & Tushar Sharma on-line! See this thread for details.
Regarding Servlet 3.0 programmatic security, when a session times out there is no way to invoke HttpServletRequest#logout().
Does the user remain logged into JAAS?
If so, what is best practice to handle logging out of JAAS after session times out?
How does the container handle the user's subsequent request to login again and create a new session after session timeout?
As an aside, what are the pros and cons of using the following three approaches to handle session timeout when using Servlet 3.0 programmatic security:
Make the @ManagedBean @SessionScoped LoginManager implement HttpSessionBindingListener and do something in valueUnbound.
Annotate a method in LoginManager with @PreDestroy.
Any other suggested approaches/ best practices advice would surely be appreciated.
I’ve looked at a lot of different solutions, and in my humble opinion Aspose is the way to go. Here’s the link: http://aspose.com
subject: How to handle session timeout when using Servlet 3.0 programmatic security