Once /logout
is called, I expect the session.invalidate()
to clear the session, and then next time when /portal/home
is called, it should redirect to auth0 login form.
But, auth0 login form is shown ONLY ONCE upon calling /portal/home
.
And for subsequent calls, without showing the auth0 login form, the user is logged in automatically showing the ‘home’ page.
This is a bug in the example code downloaded, from auth0.com.
Has anyone fixed it?
Thanks!